# Web Application Security Fundamentals Course

Canonical URL: <https://www.graduateschool.edu/courses/web-application-security-fundamentals>

## Overview

This is an intermediate course that deliberately spans two audiences who usually get trained separately. It carries enough technical grounding for the people who build and configure web applications, and enough plain-language framing for the system owners, ISSOs and contracting staff who oversee them without writing code. The shared vocabulary is the point, because a system owner, an ISSO and a developer can take this course together and come out able to talk to each other, which is what actually makes security reviews go faster. There is no lab, and that is deliberate: there is no environment to provision and no technical prerequisites, so the course can be assigned to oversight staff and developers at the same time. All interactivity is drag-and-drop and scenario prompts of the form "given this situation, what is the most appropriate action", and no lab environment is required for any module or for the final assessment.

Every topic is anchored to the federal policy landscape rather than taught generically. Module 1 is intentionally policy-heavy so the later technical modules can refer back to it, covering FISMA, the Risk Management Framework and the authorization process, Executive Order 14028 and its amendments, and Cybersecurity Framework 2.0, and it teaches something rarely taught at all: how to recognize when a memorandum has been superseded, and why confirming currency matters before relying on a policy for compliance, a skill that is rare in commercial training and directly relevant to federal compliance work. Module 2 uses the OWASP Top 10, 2025 edition, as its organizing frame and stays focused on recognizing risk rather than writing exploit code, and from there the course moves through the secure development lifecycle and the Secure Software Development Framework, then identity, access control and data protection including Zero Trust and FIPS-validated encryption, before closing on continuous monitoring, event logging and incident reporting. Assessment is by ungraded quick checks in each module plus a graded final covering all five modules proportionally, weighted toward applying concepts rather than recalling facts, at 70% to pass with unlimited retakes.

## What you'll learn

- Explain why web application security is a shared responsibility across technical and non-technical federal staff
- Identify the federal laws, executive orders and NIST, OMB and CISA guidance that govern federal web applications
- Recognize when a policy or memorandum has been superseded, and why confirming currency matters
- Recognize the most common categories of web application vulnerability and the risk each poses to federal systems and data
- Describe secure software development lifecycle practices and how they reduce risk
- Apply core secure-coding principles including input validation, output encoding, least privilege, secure defaults and failing securely
- Manage risk from third-party and open-source components
- Explain identity, access control and data protection principles, including Zero Trust and FIPS-validated encryption
- Describe federal expectations for continuous monitoring, event logging and incident reporting
- Apply all of the above to realistic scenarios without needing a technical lab

## Prerequisites

Basic familiarity with general cybersecurity concepts and everyday web application use. No development experience required.

## Curriculum

#### Module 1

- Foundations of Web Application Security and the Federal Policy Landscape
- What a web application is and why it is a common attack surface
- The CIA triad applied to federal systems
- Threat actors from nation-state to insider
- Shared responsibility across developers, system owners, ISSOs and users
- FISMA, the Risk Management Framework and the authorization process, Executive Order 14028 and its amendments, and Cybersecurity Framework 2.0
- How to tell when a policy has been superseded

#### Module 2

- Common Web Application Vulnerabilities
- How the OWASP Top 10 is developed and why federal secure-coding guidance references it
- The 2025 edition categories including broken access control, cryptographic failures, injection, insecure design and misconfiguration, vulnerable and outdated components, authentication failures, server-side request forgery, and logging and monitoring failures
- Why each is consequential for federal systems

#### Module 3

- Secure Development Practices and the Secure SDLC
- The phases of a secure development lifecycle
- Input validation, output encoding, least privilege, secure defaults and failing securely
- Security requirements and threat modeling before code is written
- Static and dynamic testing at a conceptual level
- Open-source and software supply chain risk
- How secure development supports the path to an authorization to operate

#### Module 4

- Authentication, Access Control, and Data Protection
- Authentication versus authorization
- Multifactor authentication and federal digital identity assurance levels
- Role-based and attribute-based access control and least privilege
- Zero Trust principles applied to web applications
- Protecting data at rest and in transit including FIPS-validated encryption
- Common mistakes such as exposing sensitive data in URLs and weak session management

#### Module 5

- Monitoring, Incident Response, and Ongoing Compliance
- Continuous monitoring under the Risk Management Framework
- Federal event-logging expectations for incident investigation
- Recognizing and reporting a suspected web application incident
- How FISMA reporting and periodic reauthorization keep systems accountable
- What any employee should do on suspecting a compromise

## Schedule
- Jan 12, 2027 – Jan 13, 2027 — Live Online
- Feb 25, 2027 – Feb 26, 2027 — Live Online
- Mar 29, 2027 – Mar 30, 2027 — Live Online
- Apr 13, 2027 – Apr 14, 2027 — Live Online
- May 6, 2027 – May 7, 2027 — Live Online
- Jun 29, 2027 – Jun 30, 2027 — Live Online
- Jul 12, 2027 – Jul 13, 2027 — Live Online
- Aug 5, 2027 – Aug 6, 2027 — Live Online

## Pricing

**Tuition:** $899
