Skip to content

Application Security (AppSec/DevSecOps) — OWASP, SAST/DAST/SCA

A three-day shift-left security training: integrating static analysis (SAST), dynamic analysis (DAST), and open-source component analysis (SCA) into the CI/CD cycle, aligned with OWASP Top 10 and the Cyber Resilience Act (CRA) requirements for software manufacturers.

Three tools, one integrated security pipeline

SAST, DAST, and SCA answer different questions: what’s vulnerable in the code, how does the application behave at runtime, and what known flaws does the dependency chain carry. Instead of teaching each tool in isolation, the training shows how to integrate all three into a single, coherent CI/CD pipeline with quality gates matched to the team’s maturity — so security supports delivery instead of blocking it.

Reducing false positives as a condition for effectiveness

A tool that generates dozens of alerts a day, most of them false alarms, trains teams to ignore security notifications — the exact opposite of what it was meant to achieve. The workshop spends significant time tuning scanner rules and prioritizing results by real-world exploitability, not just theoretical vulnerability classification.

The Cyber Resilience Act introduces a formal security-by-design requirement for software manufacturers selling into the EU, including a duty to report actively exploited vulnerabilities within 24 hours. The final module of the training shows how to map an existing (or newly built) AppSec programme onto these requirements before they become the subject of a compliance audit.

Benefits

  • Design and implement an integrated security pipeline combining SAST, DAST, and SCA
  • Embed OWASP Top 10 controls into code review and automated quality gates
  • Build a vulnerability management process for open-source components (SBOM, dependency management)
  • Prepare the organization for software manufacturer obligations under the Cyber Resilience Act (CRA)

Who is this training for?

DevOps engineers and platform engineers implementing security controls in CI/CD
Developers and tech leads responsible for the security of the code they ship
AppSec specialists building an application security programme for their organization
Product and engineering managers preparing the organization for Cyber Resilience Act requirements

Prerequisites

  • Basic understanding of the CI/CD process and software delivery tooling
  • Familiarity with OWASP Top 10 for web applications (helpful, introduced at the start of the training)

Training program

01

Shift-left security and the AppSec maturity model

  • The shift-left philosophy: why finding vulnerabilities earlier is cheaper and more effective
  • The AppSec programme maturity model (OWASP SAMM) and assessing your organization's starting point
  • The role of security champions within development teams
  • Integrating security into agile methodologies without slowing down delivery
02

Static analysis (SAST) in practice

  • How SAST works and the typical vulnerability classes it detects statically (injection, XSS, unsafe deserialization)
  • Integrating SAST into the CI/CD pipeline and configuring quality gates (fail build vs warning)
  • Reducing false positives and prioritizing scan results
  • Secure coding patterns as a complement to automated controls
03

Dynamic analysis (DAST) and API testing

  • How DAST works and how it differs from SAST — what each method detects
  • Automating DAST scans in staging and pre-production environments
  • API security: testing REST/GraphQL against the OWASP API Security Top 10
  • Integrating DAST results into the vulnerability management process
04

Component analysis (SCA) and software supply chain management

  • Software Composition Analysis — identifying vulnerable open-source libraries
  • Software Bill of Materials (SBOM) — generation, format, and use
  • Managing license risk and vulnerabilities in transitive dependencies
  • Responding to critical supply chain vulnerabilities (a process similar to Log4Shell)
05

Cyber Resilience Act (CRA) compliance for software manufacturers

  • Scope of CRA obligations: products with digital elements placed on the EU market
  • Security-by-design and security-by-default requirements and technical documentation
  • The obligation to report actively exploited vulnerabilities and severe incidents
  • Mapping an existing AppSec programme onto CRA requirements and CE marking

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

How does this training differ from Lead Application Security Manager and DevSecOps in our catalog?

Lead Application Security Manager is aimed at a management role building an organization-wide AppSec strategy, and the DevSecOps training focuses on the culture and collaboration processes between Dev, Sec, and Ops. This training is more hands-on and tool-focused — a step-by-step SAST/DAST/SCA integration into the CI/CD pipeline, with an emphasis on the new CRA regulatory requirement that the other trainings don't cover.

In what order should we implement SAST, DAST, and SCA — where do we start?

A typical order is: SCA first (fast identification of known vulnerabilities in dependencies, low barrier to entry), then SAST integrated into code review (catching vulnerabilities in your own code before merge), and finally DAST in a staging environment (verifying application behavior at runtime). In the training we show how to adapt this order to your organization's maturity.

How do we reduce false positives from SAST tools so the team doesn't start ignoring alerts?

The key techniques are: tuning scanner rules to your technology stack, prioritizing results by actual exploitability (not just theoretical vulnerability class), and gradually tightening quality gates instead of blocking every build immediately. In the workshop we practice rule configuration on a sample repository.

What is an SBOM, and why is it becoming mandatory?

A Software Bill of Materials is a structured list of every component (libraries, dependencies, versions) that makes up a piece of software — the equivalent of an ingredient list on food packaging. The Cyber Resilience Act and a growing number of contractual requirements for software vendors to the public sector require delivering an SBOM, so exposure to newly discovered supply-chain vulnerabilities can be assessed quickly.

How does the Cyber Resilience Act affect companies producing software sold in the EU?

The CRA requires manufacturers of products with digital elements (including software) to ensure security by design, maintain technical documentation, report actively exploited vulnerabilities within 24 hours, and maintain a security update process throughout the product's lifecycle — on pain of being unable to affix the CE mark. In the training we show how to map an existing SAST/DAST/SCA programme onto these requirements.

Klaudia Janecka
Klaudia Janecka Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90