Fundamentals of Secure Software
Keep adding new skills with 10,000+ programs for $239 (usually $399). Save now.
Fundamentals of Secure Software
Included with
Learn more
Ask Coursera
Recommended experience
Recommended experience
What you'll learn
Implement secure coding practices and integrate security into the SDLC.
Identify and mitigate application security threats using OWASP Top 10.
Strengthen cloud, container, and API security to protect modern applications.
Apply DevSecOps principles and secure CI/CD pipelines for automated security.
Skills you'll gain
- DevOps
- Cloud Platforms
- Security Testing
- Penetration Testing
- Cryptography
- DevSecOps
- Cloud Security
- Software Development Life Cycle
- Encryption
- Secure Coding
- Vulnerability Management
- Software Development
- Vulnerability Scanning
- Threat Modeling
- Configuration Management
- CI/CD
- Threat Management
- Application Security
- Vulnerability Assessments
Tools you'll learn
Details to know
11 assignments
See how employees at top companies are mastering in-demand skills
There are 13 modules in this course
Updated in May 2025.
This course now features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. In today's digital world, software security is more critical than ever. This course provides a comprehensive understanding of secure software development, equipping you with the knowledge to identify vulnerabilities, implement security best practices, and mitigate risks. You'll explore essential security principles, the Software Development Life Cycle (SDLC), and key frameworks like OWASP, NIST, and CSA. Throughout the course, youβll dive deep into secure coding practices, application security goals, and risk management strategies. Youβll gain hands-on experience with tools like WebGoat, Threat Dragon, and Microsoft Threat Model Tool. The course covers major security threats, including injection attacks, cryptographic failures, and insecure design, with demonstrations on how to mitigate these risks effectively. You'll also explore advanced topics such as DevSecOps, secure CI/CD pipelines, and supply chain security. The curriculum includes critical cloud security concepts, API protection, and vulnerability management techniques. Hands-on demos and real-world case studies ensure a practical, application-driven learning experience. This course is ideal for software developers, security engineers, and IT professionals looking to enhance their understanding of secure software development. A basic knowledge of programming and web application concepts is recommended, but no prior cybersecurity experience is required. Whether you're new to security or looking to deepen your expertise, this course will provide valuable insights into building resilient software.
In this module, we will introduce the core principles of application security, covering essential terminology and objectives. You will gain an understanding of why application security is critical and explore OWASP WebGoat, a deliberately vulnerable application used for security training.
What's included
4 videos1 reading1 assignment
4 videosβ’Total 35 minutes
- Introduction to Application Securityβ’8 minutes
- Application Security Terms and Definitionsβ’7 minutes
- Application Security Goalsβ’10 minutes
- OWASP WebGoat Demoβ’11 minutes
1 readingβ’Total 10 minutes
- Full Course Resourcesβ’10 minutes
1 assignmentβ’Total 15 minutes
- Introduction to the Course - Assessmentβ’15 minutes
In this module, we will delve into Secure SDLC, starting with an overview of application security and key industry standards. You will learn about common security risks, fundamental security goals, and leading frameworks like NIST and CSA that guide secure software development.
What's included
7 videos1 assignment
7 videosβ’Total 62 minutes
- Application Security Introductionβ’12 minutes
- Top 10sβ’10 minutes
- Application Security Terms and Definitionsβ’4 minutes
- Application Security Goalsβ’9 minutes
- Introduction to NISTβ’11 minutes
- Introduction to CSAβ’8 minutes
- API Securityβ’9 minutes
1 assignmentβ’Total 15 minutes
- Understanding Secure SDLC - Assessmentβ’15 minutes
In this module, we will explore the Defense in Depth strategy, focusing on multiple layers of security to protect applications. You will gain insights into cybersecurity roles, API security, CSP implementation, SSRF attacks, and effective vulnerability management practices.
What's included
6 videos1 assignment
6 videosβ’Total 60 minutes
- Defense in Depthβ’6 minutes
- Roles and Terms in Cybersecurityβ’11 minutes
- API Securityβ’12 minutes
- Content Security Policy (CSP)β’4 minutes
- Server-Side Request Forgery - SSRFβ’7 minutes
- Vulnerability Managementβ’18 minutes
1 assignmentβ’Total 15 minutes
- Defense in Depth - Assessmentβ’15 minutes
In this module, we will take a deep dive into the OWASP Top 10, the most critical web security risks recognized globally. Through theoretical explanations and practical demos, you will learn how vulnerabilities like Broken Access Control, Injection, and Cross-Site Scripting (XSS) are exploited and how to mitigate them effectively.
What's included
14 videos1 assignment
14 videosβ’Total 113 minutes
- Broken Access Controlβ’5 minutes
- Broken Access Control - Demoβ’8 minutes
- Cryptographic Failuresβ’10 minutes
- Injectionβ’4 minutes
- Injection Demoβ’17 minutes
- Insecure Designβ’10 minutes
- Security Misconfigurationβ’3 minutes
- Vulnerable and Outdated Componentsβ’10 minutes
- Identification and Authentication Failuresβ’7 minutes
- Identification Failures Demoβ’6 minutes
- Software and Data Integrity Failuresβ’9 minutes
- Security Logging and Monitoring Failuresβ’8 minutes
- Cross-Site Scripting (XSS)β’8 minutes
- XSS Demoβ’10 minutes
1 assignmentβ’Total 15 minutes
- Dive into the OWASP Top 10 - Assessmentβ’15 minutes
In this module, we will explore the critical aspects of supply chain security, from understanding risks to implementing proactive defenses. You will learn about Software Composition Analysis (SCA), the SLSA framework, SBOM, and essential tools like Dependency-Track and CycloneDX to manage software dependencies securely.
What's included
6 videos1 assignment
6 videosβ’Total 51 minutes
- Introduction to Supply Chain Securityβ’6 minutes
- Supply Chain Defensesβ’11 minutes
- Software Composition Analysis (SCA)β’12 minutes
- Introducing SLSAβ’6 minutes
- Software Bill of Materials (SBOM)β’10 minutes
- Dependency-Track and CycloneDXβ’6 minutes
1 assignmentβ’Total 15 minutes
- Supply Chain Security - Assessmentβ’15 minutes
In this module, we will dive into cloud and container security, focusing on securing workloads across AWS, Azure, and GCP. You will learn about identity and access management, detection controls, data protection, and incident response in AWS, along with best practices for securing containerized applications.
What's included
11 videos1 assignment
11 videosβ’Total 53 minutes
- Introduction to Cloudβ’6 minutes
- Cloud Security Conceptsβ’2 minutes
- AWS Security Pillarβ’5 minutes
- AWS Identity and Access Managementβ’6 minutes
- AWS Detection Controlsβ’4 minutes
- AWS Infrastructureβ’7 minutes
- AWS Data Protectionβ’7 minutes
- AWS Incident Responseβ’2 minutes
- AWS Application Securityβ’2 minutes
- Container Securityβ’5 minutes
- Azure and GCPβ’6 minutes
1 assignmentβ’Total 15 minutes
- Cloud and Container Security- Assessmentβ’15 minutes
In this module, we will explore the critical aspects of session management, including web sessions, JWT, and JSON Web Encryption (JWE). You will also learn about OAuth and OpenID Connect, which are widely used authentication and authorization protocols for securing modern applications.
What's included
7 videos1 assignment
7 videosβ’Total 47 minutes
- Introduction to Session Managementβ’15 minutes
- Web Sessionsβ’5 minutes
- JSON Web Token (JWT)β’7 minutes
- JWT Exampleβ’3 minutes
- JSON Web Encryption (JWE)β’6 minutes
- OAuthβ’6 minutes
- OpenID & OpenID Connectβ’4 minutes
1 assignmentβ’Total 15 minutes
- Session Management - Assessmentβ’15 minutes
In this module, we will explore risk rating methodologies and introduce threat modeling as a proactive approach to identifying and mitigating security threats. You will learn how to assess risks, apply security controls, and use industry-leading tools like the Microsoft Threat Model Tool and OWASP Threat Dragon.
What's included
9 videos1 assignment
9 videosβ’Total 77 minutes
- Risk Rating Introductionβ’15 minutes
- Risk Rating Demoβ’8 minutes
- Security Controlsβ’10 minutes
- Introduction to Threat Modelingβ’9 minutes
- Type of Threat Modelingβ’8 minutes
- Introduction to Manual Threat Modelingβ’8 minutes
- Prepping for Microsoft Threat Model Toolβ’4 minutes
- Microsoft Threat Model Tool Demoβ’9 minutes
- OWASP Threat Dragon Demoβ’6 minutes
1 assignmentβ’Total 15 minutes
- Risk Rating and Basic Threat Modeling - Assessmentβ’15 minutes
In this module, we will dive deeper into advanced threat modeling approaches, including DREAD, MITRE ATT&CK, and attack trees. You will learn how to apply these frameworks, perform hands-on demos, and implement continuous threat modeling for cloud environments using tools like Threagile.
What's included
9 videos1 assignment
9 videosβ’Total 53 minutes
- Additional Methods of Threat Modelingβ’3 minutes
- Using DREADβ’5 minutes
- Using MITRE ATT&CKβ’9 minutes
- Other Advanced Threat Modeling Techniquesβ’2 minutes
- Attack Treesβ’4 minutes
- Attack Tree Demoβ’3 minutes
- Continuous Threat Modelingβ’10 minutes
- Threagile Demoβ’14 minutes
- Threat Modeling the Cloudβ’4 minutes
1 assignmentβ’Total 15 minutes
- More Advanced Threat Modeling - Assessmentβ’15 minutes
In this module, we will explore the concepts of encryption and hashing, their applications, and their role in cybersecurity. You will gain hands-on experience with hashing techniques, password security, and Public Key Infrastructure (PKI) to understand how cryptographic principles protect sensitive data.
What's included
7 videos
7 videosβ’Total 46 minutes
- Encryption Overviewβ’7 minutes
- Encryption Use Casesβ’9 minutes
- Hashing Overviewβ’2 minutes
- Hashing Demoβ’4 minutes
- Public Key Infrastructure (PKI)β’13 minutes
- Password Managementβ’7 minutes
- Password Demoβ’3 minutes
In this module, we will explore the integration of security into DevOps, creating a DevSecOps culture and implementing security in continuous integration and continuous deployment (CI/CD). You will learn about secure development practices, vulnerability analysis, and operational security, culminating in a hands-on demo of a secure CI/CD pipeline.
What's included
9 videos
9 videosβ’Total 52 minutes
- DevOpsβ’14 minutes
- DevSecOpsβ’5 minutes
- DevSecOps Designβ’2 minutes
- DevSecOps Codeβ’3 minutes
- DevSecOps Analysisβ’6 minutes
- DevSecOps Buildβ’7 minutes
- DevSecOps Operationsβ’4 minutes
- Secure CICDβ’3 minutes
- Secure CICD Demoβ’8 minutes
In this module, we will explore various security testing techniques used to identify and mitigate vulnerabilities in applications. You will learn about SAST, DAST, IAST, and RASP, as well as security posture management, web application firewalls, and hands-on penetration testing and fuzz testing techniques.
What's included
11 videos
11 videosβ’Total 57 minutes
- SAST (Static Application Security Testing)β’7 minutes
- CodeQL Demoβ’8 minutes
- DAST (Dynamic Application Security Testing)β’5 minutes
- New Videoβ’6 minutes
- IAST (Interactive Application Security Testing)β’2 minutes
- ASPM (Application Security Posture Management)β’5 minutes
- ASPM Demoβ’7 minutes
- RASP (Runtime Application Self-Protection)β’2 minutes
- WAF (Web Application Firewall)β’7 minutes
- Penetration Testingβ’2 minutes
- Fuzz Testingβ’4 minutes
In this module, we will review the essential takeaways from the course and reinforce the importance of proactive security measures. You will leave with a strong understanding of application security principles and practical strategies to implement them effectively in your projects.
What's included
1 video2 assignments
1 videoβ’Total 13 minutes
- Conclusionβ’13 minutes
2 assignmentsβ’Total 75 minutes
- Full course assessmentβ’60 minutes
- Full Course Practice Assessmentβ’15 minutes
Instructor
Offered by
Explore more from Security
- Status: Preview
Course
- Status: Free TrialC
CertNexus
Course
- Status: Free Trial
Course
- Status: Preview
Why people choose Coursera for their career
Frequently asked questions
Yes, you can preview the first video and view the syllabus before you enroll. You must purchase the course to access content not included in the preview.
If you decide to enroll in the course before the session start date, you will have access to all of the lecture videos and readings for the course. Youβll be able to submit assignments once the session starts.
Once you enroll and your session begins, you will have access to all videos and other resources, including reading items and the course discussion forum. Youβll be able to view and submit practice assessments, and complete required graded assignments to earn a grade and a Course Certificate.
More questions
Financial aid available,
