This Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) training course provides solutions-based approach to identify and mitigate today’s most common business security risks to applications. You will learn to scan, assess and secure applications using the Fortify Static Code Analyzer (SCA) and Software Security Center (SSC). This course includes hands-on activities to:
- Identify security vulnerabilities within Fortify SCA
- Exploit vulnerabilities in a sample application
- Remediate security vulnerabilities, including the OWASP Top 10
- Update and edit Rulepacks
- Manage applications’ security issues with Fortify SSC
By attending Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) workshop, delegates will learn to:
- Scan applications thoroughly and correctly in Fortify
- Assess raw scan results to create a prioritized list of high-impact security findings
- Correctly and efficiently remediate validated security findings
- Manage security goals to ensure good progress
- Integrate Fortify products with current SDLC best practices
- Basic programming skills (able to read Java, C/C++, or .NET)
- Basic understanding of web technologies: HTTP Requests and Responses, HTML tags, JavaScript, and server-side dynamic content (JSP, ASP or similar)
- Knowledge of Web and Application development practices
- Experience developing and/or managing software development for security
- Have an understanding of the organization’s compliance requirements
The Fortify SCA (Static Code Analyzer) and SSC (Software Security Center) class is ideal for:
- Application developers who are new to or have been using the Fortify SCA and/or SSC to develop secure applications. It is also useful for development managers, security-focused QA testers, and security experts.
