|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/secure-software-design-secure-software-series-course-3-of-8/
课程评论:没有评论
**Coursera 课程摘要:安全软件设计** **课程名称:** 安全软件设计(Secure Software Design) **课程系列:** 安全软件系列,第 3 门(共 8 门) **课程概述:** 本课程是“安全软件开发基础”系列课程的第三部分,着重介绍安全软件设计的入门概念。课程旨在说明为何即使满足所有质量要求,软件仍可能存在不安全因素。本课程并非编程课程,也**不包含实际操作**。 **课程重点内容:** * **安全软件设计的必要性:** 深入理解为何需要在软件设计阶段融入安全考量。 * **攻击面评估(Attack Surface Evaluation):** 学习如何识别和评估软件的攻击面。 * **威胁建模(Threat Modeling)和攻击树(Attack Tree):** 掌握构建威胁模型和攻击树的方法,以预测和分析潜在威胁。 * **安全设计评审(Secure Design Review):** 了解如何进行安全设计评审,发现设计中的安全缺陷。 * **风险管理(Risk Management):** 学习如何管理与软件安全相关的风险。 * **定义安全架构(Define Security Architecture):** 掌握如何设计和明确软件的安全架构。 * **白板讨论(Whiteboard Discussion):** 通过讨论加深对重要安全设计主题的理解。 **目标受众:** * 希望了解安全软件开发开发原则的开发者或软件工程师。 * 希望学习以软件开发为重点的 IT 安全基础知识的学习者。 **先修要求:** * 无。 **学习目标:** * 掌握安全开发的关键方面。 * 理解 CIA 三元组(机密性、完整性、可用性)、AAA(认证、授权、审计)等安全基本概念。 * 识别构建安全软件程序所需的正确软件构建要求。 * 确定如何指定适当的软件架构以满足软件安全需求。 * 了解软件验收的通用最佳实践。 * 掌握软件程序应具备的适当软件获取和供应链要求。 * 了解安全软件的正确测试流程。 **课程结构:** 课程将涵盖课程概述、讲师介绍、先修要求,以及安全软件设计的主要模块,包括需求、攻击面评估、威胁建模、设计评审、风险管理、安全架构定义和白板讨论。课程还包括模块回顾、复习题和课程总结。 **重要提示:** 完成该系列的全部八门课程,将涵盖 CSSLP 考试目标的大约 65% 或以上。本课程强调了在软件开发早期融入安全设计的诸多优势。
Course OverviewIn this course series we cover what secure software design means and why software can meet all quality requirements and still be insecure. Please note that this course is providing introductory concepts for beginners and is NOT a programming course or has any hands on.This course specifically, Secure Software Design is meant to provide learners a foundational start in software design that is focused around security. The course covers important aspects around the need for Secure Software Design, understanding the Attack Surface Evaluation processes and what a Threat Model Attack Tree is. The course continues on to cover Secure Design Review, Risk Management, how to Define Security Architecture and a Whiteboard Discussion to name a few lessons. The course provides some review questions and also whiteboard discussions to provide insight into some important topics. Lastly, the course series covers about 65% or more of the exam objectives for the CSSLP exam when completing all eight courses! There are many benefits of designing security early which we cover in this course.This is a series of courses for learning about "Secure Software Development Fundamentals"Course 1 - Secure Software ConceptsCourse 2 - Secure Software RequirementsCourse 3 - Secure Software DesignCourse 4 - Defining Security ArchitecturesCourse 5 - Secure Software TestingCourse 6 - Secure Software AcceptanceCourse 7 - Software Deployment, Operations and MaintenanceCourse 8 - Supply Chain and Software AcquisitionWho should take this course (Target Audience)?You are a developer or software engineer and want to understandYou want to learn IT security fundamentals focused on software developmentWhat are the Couse Pre Requirements?There are no course pre-requirementWhat You'll LearnWhat are the critical aspects of secure developmentWhat is the CIA Triad, AAA and other security fundamentalsIdentify the correct software build requirements needed for a secure software programDetermine how to specify the proper software architecture to meet your software security requirementsUnderstand what the commonly accepted best practices are software acceptanceDetermine the proper software acquisition and supply chain requirements for your software programsGet to know the proper software testing procedure for a secure software program.RequirementsNo RequirementsCourse ContentsCourse Overview, Instructor Intro, Course PrereqsMain Modules covered are: Need for Secure Software Design Attack Surface Evaluation Threat Model Attack Tree Secure Design Review Risk Management Define Security Architecture Whiteboard Discussion Module Review Review Questions Course Closeout