Advanced Practices in Application Security
Keep adding new skills with 10,000+ programs for $239 (usually $399). Save now.
Recommended experience
Recommended experience
What you'll learn
Apply secure coding practices and OWASP top 10 prevention techniques to eliminate vulnerabilities during development phases.
Analyze application architectures to identify critical security threats and design comprehensive threat models for risk mitigation.
Evaluate software supply chains and implement application security controls for open-source components, dependencies, and vendor relationships.
Design secure cloud-native and container architectures with automated monitoring and compliance validation capabilities.
Skills you'll gain
- Continuous Monitoring
- Cloud Standards
- Application Security
- Dependency Analysis
- Security Controls
- Multi-Cloud
- Software Development
- IT Security Architecture
- Security Testing
- Secure Coding
- CI/CD
- Cloud-Native Computing
- Hybrid Cloud Computing
- Containerization
- Supply Chain
- Application Design
- Cloud Security
- Threat Modeling
- Application Development
Tools you'll learn
Details to know
See how employees at top companies are mastering in-demand skills
There are 6 modules in this course
As cyber threats grow in sophistication, organizations can no longer treat application security as an afterthought. This course equips software developers, cybersecurity professionals, and DevSecOps teams to embed security throughout the software development lifecycle (SDLC). You'll master practical, up-to-date application security best practices aligned with industry frameworks from NIST, OWASP, CISA, and CSA.
Learn to integrate secure coding, threat modeling, and supply chain security from the ground up. Explore secure development practices using NIST's SSDF, adopt Secure by Design principles endorsed by over 100 leading software firms, and implement controls from OWASP and CSA's Cloud Controls Matrix. Gain hands-on experience with application security testing tools for static analysis, container security, SBOMs, and threat modeling methodologies like STRIDE. Through a comprehensive fictional case study, you'll apply these skills in real-world scenarios, from legacy integration to cloud-native deployments, preparing you to lead security-first development in any organization. Stay ahead of regulatory demands and design secure software from day one.
In this course, you’ll learn how to implement advanced application security practices by embedding security throughout the software development lifecycle (SDLC). You’ll focus on real-world techniques such as secure coding, vulnerability assessment, and DevSecOps integration to anticipate and prevent cyber threats. Through expert instruction, case studies, and hands-on exercises, you’ll gain the skills to apply security controls, integrate automated security testing into pipelines, and align practices with industry standards. By the end of this course, you’ll be equipped to strengthen organizational resilience, reduce risk exposure, and lead proactive application security initiatives that protect software across cloud, mobile, IoT, and enterprise environments.
What's included
1 video1 reading
1 video•Total 3 minutes
- Intro Video to Course •3 minutes
1 reading•Total 5 minutes
- Welcome to the Course: Course Overview•5 minutes
In this module, you’ll learn how to embed security directly into your applications and development processes. You’ll explore Secure by Design principles, secure coding techniques, and secure configuration practices to prevent critical vulnerabilities. Through practical demonstrations, static and dynamic application security testing, and runtime protection strategies, you’ll develop the skills to identify, mitigate, and manage vulnerabilities throughout the software development lifecycle. This module emphasizes proactive security practices aligned with industry standards such as OWASP Top 10 and SANS Top 25 to ensure robust, production-ready applications.
What's included
10 videos1 reading1 assignment1 peer review2 discussion prompts
10 videos•Total 60 minutes
- Module Introduction•3 minutes
- Secure by Design Principles•5 minutes
- Secure Coding Practices •5 minutes
- Secure Configuration and Defaults•6 minutes
- Prevention of OWASP Top 10 •6 minutes
- Stopping Insecure Design and Misconfiguration Failures•6 minutes
- Defending Against Supply Chain Attacks and Logging Failures•10 minutes
- Code Testing for Vulnerabilities •5 minutes
- Testing an Application for Run-Time Vulnerabilities •7 minutes
- Run-Time Protection •7 minutes
1 reading•Total 5 minutes
- Foundations Section of the OWASP Developer Guide•5 minutes
1 assignment•Total 20 minutes
- Secure Development and Code Security •20 minutes
1 peer review•Total 10 minutes
- Hands-On-Learning: Secure Coding Practices: Identifying and Fixing Vulnerable Code in GitHub Codespaces•10 minutes
2 discussion prompts•Total 20 minutes
- OWASP Top 10 Vulnerability Analysis and Prevention Strategy •10 minutes
- Implementing Proactive Security Transformation in Development Teams•10 minutes
In this module, you’ll learn how to systematically identify and analyze security threats before they become costly vulnerabilities. You’ll explore industry-standard methodologies, including STRIDE, and gain hands-on experience with threat modeling tools like OWASP Threat Dragon, attack trees, and Rapid Threat Modeling Prototyping (RTMP). By applying these techniques to real-world scenarios, you’ll develop the skills to anticipate attack vectors, prioritize risks using OWASP and CVSS frameworks, and translate findings into actionable security controls that strengthen application defenses from design through deployment.
What's included
10 videos1 reading1 assignment1 peer review1 discussion prompt
10 videos•Total 59 minutes
- Intro Video to Module •2 minutes
- Threats vs Risks •5 minutes
- Intro to Threat Modelling •5 minutes
- Utilizing STRIDE For Threat Modelling •6 minutes
- Threat Modelling with OWASP Threat Dragon•8 minutes
- Using Attack Trees in Threat Modelling •6 minutes
- Completing a Rapid Threat Modeling Prototyping (RTMP) •6 minutes
- Risk Rating Using OWASP Risk Rating•7 minutes
- CVSS Scoring for Vulnerability Management•7 minutes
- Transforming Threats into Secure Designs•7 minutes
1 reading•Total 5 minutes
- NIST Threat Modeling Guidelines •5 minutes
1 assignment•Total 20 minutes
- Threat Modeling Best Practices •20 minutes
1 peer review•Total 10 minutes
- Hands-On-Learning: Attack Path Modeling: Creating Attack Trees with Deciduous •10 minutes
1 discussion prompt•Total 10 minutes
- Threat Prioritization and Mitigation Strategy Development•10 minutes
In this module, you’ll learn how to secure the software supply chain and CI/CD pipelines critical to modern development. You’ll explore techniques for evaluating and securing open-source components, third-party dependencies, and vendor relationships while integrating automated security testing throughout development pipelines. Hands-on exercises with Software Bill of Materials (SBOM) creation, dependency management, and monitoring tools equip you to prevent supply chain attacks, ensure compliance with industry standards, and maintain secure DevOps workflows without slowing delivery.
What's included
10 videos1 reading1 assignment1 peer review2 discussion prompts
10 videos•Total 60 minutes
- Intro Video to Module •2 minutes
- Software Supply Chain Threat Landscape •6 minutes
- Software Bill of Materials (SBOM) Fundamentals•5 minutes
- Dependency Management and Open-Source Risk Assessment •7 minutes
- SLSA Framework and Build Provenance •6 minutes
- Artifact Integrity and Code Signing •9 minutes
- Vendor Risk Assessment and Third-Party Security •8 minutes
- Continuous Supply Chain Monitoring•6 minutes
- Compliance and Regulatory Requirements •5 minutes
- Supply Chain Incident Response and Recovery •7 minutes
1 reading•Total 5 minutes
- Securing the Software Supply Chain •5 minutes
1 assignment•Total 20 minutes
- Supply Chain Security •20 minutes
1 peer review•Total 10 minutes
- Hands-On-Learning: Software Supply Chain Security: SBOM Generation and Vulnerability Analysis with Syft and Grype •10 minutes
2 discussion prompts•Total 20 minutes
- Open-Source Component Evaluation and Strategic Dependency Management•10 minutes
- Implementing Continuous Supply Chain Monitoring Strategy•10 minutes
In this module, you’ll learn how to secure cloud-native applications, containers, and serverless environments while implementing continuous monitoring and governance. You’ll explore cloud security architectures using CSA Cloud Controls Matrix standards, container and runtime security practices, and Infrastructure-as-Code (IaC) automation for secure deployments. Hands-on exercises with monitoring tools, Kubernetes RBAC, and secrets management help you protect dynamic cloud workloads, detect threats in real time, and maintain compliance across hybrid and multi-cloud environments.
What's included
10 videos1 reading1 assignment1 peer review2 discussion prompts
10 videos•Total 49 minutes
- Intro Video to Module •3 minutes
- Cloud-Native Security Fundamental •6 minutes
- Container and Serverless Security •5 minutes
- Cloud Security Automation and Infrastructure as Code (IaC) Security •6 minutes
- Kubernetes Security Architecture and RBAC •5 minutes
- Container and Registry Security •5 minutes
- Runtime Protection and Behavioral Monitoring •5 minutes
- Network Security and Micro-Segmentation •5 minutes
- Secrets Management and Data Protection •5 minutes
- Compliance and Governance in Cloud-Native Environments •4 minutes
1 reading•Total 5 minutes
- CCM v4.0 Implementation Guidelines•5 minutes
1 assignment•Total 20 minutes
- Cloud Security and Container Security •20 minutes
1 peer review•Total 10 minutes
- Hands-On-Learning: Cloud-Native Security: Container Vulnerability Scanning and Security Reporting with Trivy •10 minutes
2 discussion prompts•Total 20 minutes
- Container Runtime Security Monitoring and Threat Detection•10 minutes
- Cloud Migration Security Strategy and Monitoring•10 minutes
In this final module, you will synthesize your learning across secure coding, threat modeling, supply chain protection, and cloud-native security practices. You’ll bring these core concepts together in a hands-on capstone project where you will perform a complete threat modeling exercise using OWASP Threat Dragon. This project demonstrates your ability to identify risks, design effective mitigations, and integrate security into the software development lifecycle. By the end, you will be prepared to showcase your expertise in applying industry-standard frameworks and tools to build secure, resilient applications that align with both technical requirements and organizational goals.
What's included
1 video1 peer review
1 video•Total 3 minutes
- Course Wrap-up Video •3 minutes
1 peer review•Total 60 minutes
- Project: Comprehensive Application Security Assessment: From Code to Container •60 minutes
Instructors
Offered by
Explore more from Security
- Status: Free Trial
- Status: Free Trial
Course
- Status: Free Trial
Course
Why people choose Coursera for their career
Frequently asked questions
Application security is the discipline of protecting software from threats by integrating safeguards across the entire software development lifecycle (SDLC). It is critical because applications are among the most targeted assets in any organization, and a single unaddressed vulnerability can result in data breaches, financial loss, and regulatory penalties. For this reason, modern teams build security in from day one rather than treating it as an afterthought. This course is designed to teach the security-first approach.
The main purpose of application security is to identify, prevent, and remediate vulnerabilities before they can be exploited. Rather than adding protection after development, it embeds security throughout the SDLC to keep software safe, reliable, and compliant. This course develops that capability through application security best practices aligned with industry frameworks from NIST, OWASP, CISA, and CSA.
Application security skills support roles such as application security engineer, security analyst, DevSecOps engineer, secure software developer, and security architect. As organizations increasingly embed security into the development lifecycle, professionals who can apply secure coding and threat modeling are in growing demand across both development and security teams.
More questions
Financial aid available,
¹ Some assignments in this course are AI-graded. For these assignments, your data will be used in accordance with Coursera's Privacy Notice.
