Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

Fortify SCA (Static Code Analyzer) and SSC (Software Security Center)

( Duration: 4 Days )

This Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) training course provides solutions-based approach to identify and mitigate today’s most common business security risks to applications. You will learn to scan, assess and secure applications using the Fortify Static Code Analyzer (SCA) and Software Security Center (SSC). This course includes hands-on activities to:

  • Identify security vulnerabilities within Fortify SCA
  • Exploit vulnerabilities in a sample application
  • Remediate security vulnerabilities, including the OWASP Top 10
  • Update and edit Rulepacks
  • Manage applications’ security issues with Fortify SSC

By attending Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) workshop, delegates will learn to:

  • Scan applications thoroughly and correctly in Fortify
  • Assess raw scan results to create a prioritized list of high-impact security findings
  • Correctly and efficiently remediate validated security findings
  • Manage security goals to ensure good progress
  • Integrate Fortify products with current SDLC best practices

  • Basic programming skills (able to read Java, C/C++, or .NET)
  • Basic understanding of web technologies: HTTP Requests and Responses, HTML tags, JavaScript, and server-side dynamic content (JSP, ASP or similar)
  • Knowledge of Web and Application development practices
  • Experience developing and/or managing software development for security
  • Have an understanding of the organization’s compliance requirements

The Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) class is ideal for:

  • Application developers who are new to or have been using the Fortify SCA and/or SSC to develop secure applications. It is also useful for development managers, security-focused QA testers, and security experts.

COURSE AGENDA

1

Introduction to Application Security

  • Introduction to securing your applications
2

OWASP Top 10 Vulnerabilities & Hands-On Hacking

  • Recognize the OWASP Top 10 vulnerabilities
3

Introduction to Remediation

  • Perform a basic Threat Model and Risk Assessment
4

Introduction to Fortify Administration

  • Installing Fortify
  • Recognize how Fortify scans
5

Audit Workbench (AWB) Scan Results

  • Navigate Audit Workbench
6

Fortify SCA (Static Code Analyzer)

  • Describe the Scanning Process
  • Explain the function of each Analyzer
7

Plugins (Eclipse and Visual Studio)

  • Install and use the plugins Visual Studio and Eclipse
8

Data Validation

  • Select the right data validation for a particular situation
  • Extend data validation libraries
9

Analysis Trace and Remediating Vulnerabilities

  • Read the analysis trace
  • Remediate vulnerabilities
10

Custom Rules

  • Build a rule
11

Fortify SSC (Software Security Center)

  • Use the SSC to manage your applications
  • Run reports

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X