Course Overview

This course is perfect for software developers, security engineers, and IT professionals who are responsible for building and maintaining secure applications. It covers key concepts that address the growing need for secure software to mitigate evolving cybersecurity threats.

This course begins with an introduction to secure software development, discussing why security is critical and outlining major software vulnerabilities. You'll explore the evolution of software development methodologies and the core principles of secure software development, including a detailed look at Microsoft's SDL. The course then delves into the core phases of the SDL, including the training, design, implementation, verification, and response phases. Topics like threat modeling (STRIDE vs PASTA), secure coding practices, penetration testing, and vulnerability management are comprehensively covered. Additionally, you'll learn about the supporting security activities, release and deployment processes, and the continuous improvement of the SDL through ongoing training and threat monitoring.

By the end of this course, you will gain a practical understanding of how to apply Microsoft SDL for building secure software, along with tools and techniques to continuously improve the process.

The necessary resources for this course are in the "Resources" section of Video 1.1. You can also access them through this direct link - https://github.com/ec-council-learning/Microsoft-Security-Development-Lifecycle-SDL-for-Secure-Software

What You Will Learn

  • Master the implementation of Microsoft Security Development Lifecycle (SDL).
  • Understand secure design concepts like attack surface reduction and defense in depth.
  • Perform security and privacy risk assessments and define security requirements.

Program Curriculum

  • Introduction to Software and Security
  • Evolution and Principles of Secure Software Development
  • Chapter 1 Quiz

  • History and Evolution of Microsoft SDL
  • Training and Requirements Phase
  • Design Phase and Threat Modeling
  • Implementation Phase and Secure Practices
  • Verification and Release Phases
  • Response Phase and Post-release Activities
  • Chapter 2 Quiz

  • How to Support Security Activities?
  • Phases of Supporting Security Activities
  • Chapter 3 Quiz

  • Overview of Security Verification Activities
  • Hands-on Exercises
  • Chapter 4 Quiz

  • Release and Deployment Process Overview
  • Security in the Release Cycle
  • Release Candidate and Approval
  • Chapter 5 Quiz

  • Overview of Continuous Improvement in SDL
  • Incorporating Lessons and Threat Monitoring
  • Ongoing Training and SDL Process Updates
  • Chapter 6 Quiz

Summary

Load more modules

Instructor

James Vu

James is an experienced software security professional with extensive knowledge of secure software development practices. With a passion for teaching and a deep understanding of Microsoft SDL, James is dedicated to helping professionals create secure software.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8