Home/Training/Certified Application Security Engineer - Java

Programme Detail

Certified Application Security Engineer - Java

C|ASE Java trains developers and application-security professionals to integrate security throughout the Java software-development lifecycle. The programme covers...

Application SecurityRegistration Open

Programme overview

C|ASE Java trains developers and application-security professionals to integrate security throughout the Java software-development lifecycle. The programme covers security requirements, architecture, input validation, identity controls, cryptography, sessions, error handling, testing, deployment, and maintenance. Participants will apply secure-design and secure-coding principles through examples, code-review activities, threat modelling, testing, and remediation exercises relevant to modern applications.

Programmes can be delivered via

HRD Corp Claimable
Yayasan Peneraju aligned
EC-Council

At a glance

Course code
EC-007
Provider
EC-Council
Category
Application Security
Status
Registration Open
Duration
3 days
Price
RM 4,700

What participants should gain

  • Identify application threats and security requirements
  • Design secure Java applications and architectures
  • Implement secure input validation, authentication, authorisation, and cryptography
  • Perform static and dynamic application-security testing
  • Deploy and maintain applications using secure practices

Participant readiness

  • Recommended: at least two years of Java development or software-security experience
  • Working knowledge of object-oriented programming and web applications
  • Familiarity with the software-development lifecycle

Who this course is for

  • Java or .NET developers, application engineers, technical leads, and architects
  • Application-security, DevSecOps, testing, and code-review professionals
  • Teams responsible for secure software design, development, testing, and maintenance

How the course is delivered

This programme will be conducted through interactive lectures, secure-coding demonstrations, threat-modelling workshops, code-review exercises, testing activities, case studies, and remediation discussions.

This programme will be conducted through interactive lectures, secure-coding demonstrations, threat-modelling workshops, code-review exercises, testing activities, case studies, and remediation discussions | By enquiry

Course outline

Module and topic breakdown

Module 1: Understanding Application Security, Threats, and Attacks

Application threat landscape, attack surfaces, vulnerabilities, and secure-development responsibilities

Module 2: Security Requirements Gathering

Deriving security requirements from business, data, threat, regulatory, and architectural needs

Module 3: Secure Application Design and Architecture

Trust boundaries, data flows, attack surfaces, components, dependencies, and security zones

Module 4: Secure Coding Practices for Input Validation

Allow-list validation, canonicalisation, type, range, length, and format controls

Module 5: Secure Coding Practices for Authentication and Authorization

Identity proofing, credential storage, password policy, multifactor authentication, and federation

Module 6: Secure Coding Practices for Cryptography

Secure coding standards, defensive programming, input handling, output encoding, and safe APIs

Module 7: Secure Coding Practices for Session Management

Session creation, identifiers, cookies, timeouts, renewal, logout, and invalidation

Module 8: Secure Coding Practices for Error Handling

Safe exception handling, consistent failure behaviour, and user-friendly messages

Module 9: Static and Dynamic Application Security Testing

Application threat landscape, attack surfaces, vulnerabilities, and secure-development responsibilities

Module 10: Secure Deployment and Maintenance

Secure build artefacts, configuration, secrets, dependencies, environments, and release approvals

Assessment and completion

  • Continuous knowledge checks and facilitator feedback throughout the programme
  • Completion of guided exercises, scenarios, labs, or case-study activities applicable to the course
  • Final review or practical activity to confirm understanding of the stated course objectives
  • Official EC-Council examination and certification requirements depend on the selected training package and current exam version

Availability

This programme has a public intake path. Use the enquiry form below to confirm the next available session or a private cohort.

Programme enquiry

Discuss pricing, delivery, or corporate customisation

Use this form to confirm availability, request pricing clarification, or discuss a private cohort for your organisation.