Application Security (AppSec/DevSecOps) — OWASP, SAST/DAST/SCA
A three-day shift-left security training: integrating static analysis (SAST), dynamic analysis (DAST), and open-source component analysis (SCA) into the CI/CD cycle, aligned with OWASP Top 10 and the Cyber Resilience Act (CRA) requirements for software manufacturers.
Three tools, one integrated security pipeline
SAST, DAST, and SCA answer different questions: what’s vulnerable in the code, how does the application behave at runtime, and what known flaws does the dependency chain carry. Instead of teaching each tool in isolation, the training shows how to integrate all three into a single, coherent CI/CD pipeline with quality gates matched to the team’s maturity — so security supports delivery instead of blocking it.
Reducing false positives as a condition for effectiveness
A tool that generates dozens of alerts a day, most of them false alarms, trains teams to ignore security notifications — the exact opposite of what it was meant to achieve. The workshop spends significant time tuning scanner rules and prioritizing results by real-world exploitability, not just theoretical vulnerability classification.
The CRA turns AppSec from good practice into a legal obligation
The Cyber Resilience Act introduces a formal security-by-design requirement for software manufacturers selling into the EU, including a duty to report actively exploited vulnerabilities within 24 hours. The final module of the training shows how to map an existing (or newly built) AppSec programme onto these requirements before they become the subject of a compliance audit.
Benefits
- Design and implement an integrated security pipeline combining SAST, DAST, and SCA
- Embed OWASP Top 10 controls into code review and automated quality gates
- Build a vulnerability management process for open-source components (SBOM, dependency management)
- Prepare the organization for software manufacturer obligations under the Cyber Resilience Act (CRA)
Who is this training for?
Prerequisites
- Basic understanding of the CI/CD process and software delivery tooling
- Familiarity with OWASP Top 10 for web applications (helpful, introduced at the start of the training)
Training program
Shift-left security and the AppSec maturity model
- The shift-left philosophy: why finding vulnerabilities earlier is cheaper and more effective
- The AppSec programme maturity model (OWASP SAMM) and assessing your organization's starting point
- The role of security champions within development teams
- Integrating security into agile methodologies without slowing down delivery
Static analysis (SAST) in practice
- How SAST works and the typical vulnerability classes it detects statically (injection, XSS, unsafe deserialization)
- Integrating SAST into the CI/CD pipeline and configuring quality gates (fail build vs warning)
- Reducing false positives and prioritizing scan results
- Secure coding patterns as a complement to automated controls
Dynamic analysis (DAST) and API testing
- How DAST works and how it differs from SAST — what each method detects
- Automating DAST scans in staging and pre-production environments
- API security: testing REST/GraphQL against the OWASP API Security Top 10
- Integrating DAST results into the vulnerability management process
Component analysis (SCA) and software supply chain management
- Software Composition Analysis — identifying vulnerable open-source libraries
- Software Bill of Materials (SBOM) — generation, format, and use
- Managing license risk and vulnerabilities in transitive dependencies
- Responding to critical supply chain vulnerabilities (a process similar to Log4Shell)
Cyber Resilience Act (CRA) compliance for software manufacturers
- Scope of CRA obligations: products with digital elements placed on the EU market
- Security-by-design and security-by-default requirements and technical documentation
- The obligation to report actively exploited vulnerabilities and severe incidents
- Mapping an existing AppSec programme onto CRA requirements and CE marking
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
How does this training differ from Lead Application Security Manager and DevSecOps in our catalog?
Lead Application Security Manager is aimed at a management role building an organization-wide AppSec strategy, and the DevSecOps training focuses on the culture and collaboration processes between Dev, Sec, and Ops. This training is more hands-on and tool-focused — a step-by-step SAST/DAST/SCA integration into the CI/CD pipeline, with an emphasis on the new CRA regulatory requirement that the other trainings don't cover.
In what order should we implement SAST, DAST, and SCA — where do we start?
A typical order is: SCA first (fast identification of known vulnerabilities in dependencies, low barrier to entry), then SAST integrated into code review (catching vulnerabilities in your own code before merge), and finally DAST in a staging environment (verifying application behavior at runtime). In the training we show how to adapt this order to your organization's maturity.
How do we reduce false positives from SAST tools so the team doesn't start ignoring alerts?
The key techniques are: tuning scanner rules to your technology stack, prioritizing results by actual exploitability (not just theoretical vulnerability class), and gradually tightening quality gates instead of blocking every build immediately. In the workshop we practice rule configuration on a sample repository.
What is an SBOM, and why is it becoming mandatory?
A Software Bill of Materials is a structured list of every component (libraries, dependencies, versions) that makes up a piece of software — the equivalent of an ingredient list on food packaging. The Cyber Resilience Act and a growing number of contractual requirements for software vendors to the public sector require delivering an SBOM, so exposure to newly discovered supply-chain vulnerabilities can be assessed quickly.
How does the Cyber Resilience Act affect companies producing software sold in the EU?
The CRA requires manufacturers of products with digital elements (including software) to ensure security by design, maintain technical documentation, report actively exploited vulnerabilities within 24 hours, and maintain a security update process throughout the product's lifecycle — on pain of being unable to affix the CE mark. In the training we show how to map an existing SAST/DAST/SCA programme onto these requirements.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.