OWASP Web Security Testing Guide ( owaspwstg | 21 hours )

Prerequisites:
  • A general understanding of web development lifecycle
  • Experience in web application development, security, and testing

Audience

  • Developers
  • Engineers
  • Architects
Overview:

The Web Security Testing Guide (WSTG) is a community-led, open-source testing resource that provides a comprehensive framework in performing security testing for web applications and services. The Open Web Application Security Project (OWASP) Foundation and its online community continuously develop the WSTG.

This instructor-led, live training (online or onsite) is aimed at developers, engineers, and architects who wish to apply the WSTG testing framework, principles, and techniques to secure their web applications and services.

By the end of this training, participants will be able to:

  • Use the WSTG to implement testing processes and techniques in the web development lifecycle.
  • Explore different testing techniques to customize the WSTG framework based on business needs.
  • Perform various security testing methods to protect web applications from risks and attacks.
  • Create an assessment report to document security testing findings and results.

Format of the Course

  • Interactive lecture and discussion.
  • Lots of exercises and practice.
  • Hands-on implementation in a live-lab environment.

Course Customization Options

  • To request a customized training for this course, please contact us to arrange.
Course Outline:

Introduction

Overview of Web Security Testing Guide

  • The OWASP Testing Project
  • Tailoring and prioritizing for organizations
  • Testing principles and techniques
  • Security testing objectives and requirements

Exploring Various Testing Techniques

  • Manual inspections and reviews
  • Threat modeling
  • Source code review
  • Penetration testing
  • Security test integration and data analysis

Understanding the OWASP Testing Framework

  • Activities from development to deployment
  • Maintenance and operations
  • Lifecycle end-to-end testing framework and workflow
  • Penetration testing methodologies

Performing Web Application Security Testing

  • Information gathering
  • Configuration and deployment management testing
  • Identity management testing
  • Authentication and authorization testing
  • Session management testing
  • Input validation testing
  • Testing for error handling
  • Testing for weak cryptography
  • Business logic testing
  • Client-side testing
  • API testing

Reporting the Testing Assessment and Results

  • Introduction section
  • Executive summary
  • Findings section
  • Appendices

Getting Involved in the Web Security Testing Guide

  • Referencing and linking WSTG scenarios
  • Code of conduct
  • Contribution guide
  • Feature requests and feedback

Summary and Conclusion

Sites Published:

United Arab Emirates - OWASP Web Security Testing Guide

Qatar - OWASP Web Security Testing Guide

Egypt - OWASP Web Security Testing Guide

Saudi Arabia - OWASP Web Security Testing Guide

South Africa - OWASP Web Security Testing Guide

Brasil - OWASP Web Security Testing Guide

Canada - OWASP Web Security Testing Guide

中国 - OWASP Web Security Testing Guide

香港 - OWASP Web Security Testing Guide

澳門 - OWASP Web Security Testing Guide

台灣 - OWASP Web Security Testing Guide

USA - OWASP Web Security Testing Guide

Österreich - OWASP Web Security Testing Guide

Schweiz - OWASP Web Security Testing Guide

Deutschland - OWASP Web Security Testing Guide

Czech Republic - OWASP Web Security Testing Guide

Denmark - OWASP Web Security Testing Guide

Estonia - OWASP Web Security Testing Guide

Finland - OWASP Web Security Testing Guide

Greece - OWASP Web Security Testing Guide

Magyarország - OWASP Web Security Testing Guide

Ireland - OWASP Web Security Testing Guide

Israel - OWASP Web Security Testing Guide

Luxembourg - OWASP Web Security Testing Guide

Latvia - OWASP Web Security Testing Guide

España - OWASP Web Security Testing Guide

Italia - OWASP Web Security Testing Guide

Lithuania - OWASP Web Security Testing Guide

Nederland - OWASP Web Security Testing Guide

Norway - OWASP Web Security Testing Guide

Portugal - OWASP Web Security Testing Guide

România - OWASP Web Security Testing Guide

Sverige - OWASP Web Security Testing Guide

Türkiye - OWASP Web Security Testing Guide

Malta - OWASP Web Security Testing Guide

Belgique - OWASP Web Security Testing Guide

France - OWASP Web Security Testing Guide

日本 - OWASP Web Security Testing Guide

Australia - OWASP Web Security Testing Guide

Malaysia - OWASP Web Security Testing Guide

New Zealand - OWASP Web Security Testing Guide

Philippines - OWASP Web Security Testing Guide

Singapore - OWASP Web Security Testing Guide

Thailand - OWASP Web Security Testing Guide

Vietnam - OWASP Web Security Testing Guide

India - OWASP Web Security Testing Guide

Argentina - OWASP Web Security Testing Guide

Chile - OWASP Web Security Testing Guide

Costa Rica - OWASP Web Security Testing Guide

Ecuador - OWASP Web Security Testing Guide

Guatemala - OWASP Web Security Testing Guide

Colombia - OWASP Web Security Testing Guide

México - OWASP Web Security Testing Guide

Panama - OWASP Web Security Testing Guide

Peru - OWASP Web Security Testing Guide

Uruguay - OWASP Web Security Testing Guide

Venezuela - OWASP Web Security Testing Guide

Polska - OWASP Web Security Testing Guide

United Kingdom - OWASP Web Security Testing Guide

South Korea - OWASP Web Security Testing Guide

Pakistan - OWASP Web Security Testing Guide

Sri Lanka - OWASP Web Security Testing Guide

Bulgaria - OWASP Web Security Testing Guide

Bolivia - OWASP Web Security Testing Guide

Indonesia - OWASP Web Security Testing Guide

Kazakhstan - OWASP Web Security Testing Guide

Moldova - OWASP Web Security Testing Guide

Morocco - OWASP Web Security Testing Guide

Tunisia - OWASP Web Security Testing Guide

Kuwait - OWASP Web Security Testing Guide

Oman - OWASP Web Security Testing Guide

Slovakia - OWASP Web Security Testing Guide

Kenya - OWASP Web Security Testing Guide

Nigeria - OWASP Web Security Testing Guide

Botswana - OWASP Web Security Testing Guide

Slovenia - OWASP Web Security Testing Guide

Croatia - OWASP Web Security Testing Guide

Serbia - OWASP Web Security Testing Guide

Bhutan - OWASP Web Security Testing Guide

Nepal - OWASP Web Security Testing Guide