Secure Development Course for PCI DSS

Training methodology oriented to Secure Development for companies that develop web applications that are subject to PCI DSS due to their own or their clients' requirements. With additional modules specific to programming languages, in compliance with version 4.0.1 of the standard.

formacion para desarrollo seguro pci dss

Training objective

Secure Coding


To provide software development departments with the knowledge and techniques of secure coding, necessary to design, develop, evaluate and put into production secure applications. This knowledge will enable them to acquire the criteria to identify and solve common problems related to coding vulnerabilities.

Planning and Development


This comprehensive PCI DSS training provides software developers, testers and software architects with a complete foundation for planning and developing robust and secure applications by design, thus assisting in the process of achieving PCI DSS compliance.

Who is the target audience?

People involved in application development:

Software engineers

Developers

Testers

Devops

Devsecops

Logical security managers

Project managers

Etc.

Training itinerary

Training itinerary Training itinerary

BOTECH Academy's secure development training focuses on Web vulnerabilities classified by OWASP as high risk and its Application Security Verification Standard (ASVS).

During this training, vulnerabilities will be explained theoretically with practical demonstrations and the necessary countermeasures to mitigate them.

The course content, with a total duration of 8 hours, has been developed to enable participants of different knowledge levels to identify vulnerabilities and apply the necessary countermeasures to increase the security of applications in order to create applications that are fundamentally flawless and secure.

Emphasis has been placed on meeting the essential security needs of quality assurance testers, web application developers and cybersecurity experts.

Laboratory

Platform entirely developed by BOTECH's cybersecurity team, which allows students, through exercises, to put their knowledge into practice, strengthen and consolidate it.

  • During the exercises, real vulnerable code is executed, which allows to know how a vulnerability behaves in non-fictional scenarios.
  • It has a sandbox: a closed test environment designed to safely experiment with web or software development projects.
  • It has an API to be used internally to manage platform users (registrations, cancellations, queries, etc.), in addition to other functions.

Laboratory coding exercises:

Authentication

Omission of authentication

Authorization (Access Control)

Insecure reference to objects

Inclusion of local files

Incorrect authentication

Cross-Site Request Forgery (CSRF)

Cross Site Scripting (XSS)

SQL Code Injection (SQLi)

Command Injection

File Upload

Train your team so that they are not the weakest link in the security chain. Ask us!

Send us an email to info@botech.info or fill out the following contact form.