Cybersecurity and AI Architecture Fellow of the British Computer Society (FBCS)
3-Day Course + Exam · Certification · ASVS 5.0
Certification · SEC-501

Certified Secure Developer

Prove you can write secure code. This three-day certification course covers all 17 chapters of the OWASP ASVS 5.0 with hands-on implementation, followed by a four-hour practical exam. Find, fix and verify vulnerabilities across Python, Node.js, Java and Go. Pass and earn the CyberSecAI Certified Secure Developer credential.

SEC-501. The syllabus

Three days of instruction, one practical exam

Comprehensive coverage of all 17 ASVS 5.0 chapters with hands-on exercises in four languages. The certification exam is a 4-hour practical. (Times are approximate.)

Day 1

ASVS Chapters 1-6

S1-00 Course Introduction and Certification Overview 0.5 hr

Overview of the CyberSecAI Certified Secure Developer certification. Understand the exam format (4-hour practical), the passing criteria, and how the three days of instruction prepare you. Review the ASVS 5.0 structure and how all 17 chapters are covered across the course.

S1-01 V1: Encoding, Escaping and Sanitization 1.5 hrs

Comprehensive coverage of ASVS Chapter 1. Implement context-aware output encoding for every context. Test for bypass techniques. Verify against every Chapter 1 requirement. Hands-on exercises in Python and Node.js.

S1-02 V2: Validation and Business Logic 1.5 hrs

Comprehensive coverage of ASVS Chapter 2. Implement server-side validation with strict schemas. Cover type coercion, mass assignment, and business logic validation. Verify against every Chapter 2 requirement.

S1-03 V3: Web Frontend Security 1 hr

Comprehensive coverage of ASVS Chapter 3. CSP, SRI, secure cookies, CSRF tokens, Trusted Types. Verify against every Chapter 3 requirement.

S1-04 V4: HTTP Security 1 hr

Comprehensive coverage of ASVS Chapter 4. Security headers (HSTS, X-Content-Type-Options, CORP, COEP, COOP), HTTP method handling, and request/response validation. Verify against every Chapter 4 requirement.

S1-05 V5: Files and Resources 1 hr

Comprehensive coverage of ASVS Chapter 5. File upload validation, path traversal prevention, resource limits, and safe file serving. Verify against every Chapter 5 requirement.

S1-06 V6: Authentication 1.5 hrs

Comprehensive coverage of ASVS Chapter 6. Password hashing (Argon2id), MFA, credential recovery, account lockout, and HIBP integration. Verify against every Chapter 6 requirement.

Day 2 Morning

ASVS Chapters 7-11

S1-07 V7: Session Management 1.5 hrs

Comprehensive coverage of ASVS Chapter 7. Session ID generation, binding, timeout, invalidation, and fixation prevention. Verify against every Chapter 7 requirement.

S1-08 V8: Access Control 1.5 hrs

Comprehensive coverage of ASVS Chapter 8. RBAC, ABAC, object-level authorization, and deny-by-default. Verify against every Chapter 8 requirement.

S1-09 V9: API and Web Service Security 1.5 hrs

Comprehensive coverage of ASVS Chapter 9. REST and GraphQL security, rate limiting, content-type validation, and API-specific authentication. Verify against every Chapter 9 requirement.

Day 2 Afternoon

ASVS Chapters 10-14

S1-10 V10: AI/LLM Security 1 hr

Comprehensive coverage of ASVS Chapter 10 on AI and LLM security. Prompt injection, tool poisoning, MCP security, and agent trust boundaries. Verify against every Chapter 10 requirement.

S1-11 V11: Cryptography 1.5 hrs

Comprehensive coverage of ASVS Chapter 11. AES-GCM, ECDSA, key management, TLS configuration, and certificate handling. Verify against every Chapter 11 requirement.

S1-12 V12: Error Handling and Logging 1 hr

Comprehensive coverage of ASVS Chapters 12 and 16. Secure error handling, structured logging, audit trails, and tamper-evident logs. Verify against every requirement in both chapters.

S1-13 V13: Configuration and V14: Data Protection 1.5 hrs

Comprehensive coverage of ASVS Chapters 13 and 14. Secret management, environment separation, data classification, encryption at rest, and data minimization. Verify against every requirement in both chapters.

Day 2 Evening

ASVS Chapters 15-17 and Prompt Pack

S1-14 V15: Dependency, V16: Logging, V17: Build 1.5 hrs

Comprehensive coverage of the remaining ASVS chapters. Dependency management, SBOM, secure build pipelines, and reproducible builds. Verify against every requirement.

S1-15 ASVS Secure Coder Prompt Pack Deep Dive 1 hr

Master the Prompt Pack. Use it to generate verification tests for every ASVS chapter. Practice turning requirements into AI-assisted code that passes verification. Build a personal library of prompt templates for ongoing use.

Day 3

Exercises and Exam

S1-16 Practical Secure Coding Exercises: Python and Node.js 1.5 hrs

Timed exercises implementing secure patterns in Python and Node.js. Cover the most commonly tested vulnerability classes: injection, authentication, authorization, cryptography, and session management. Each exercise is scored against ASVS requirements.

S1-17 Practical Secure Coding Exercises: Java and Go 1.5 hrs

Timed exercises implementing secure patterns in Java and Go. Same vulnerability classes, different language patterns. Each exercise is scored against ASVS requirements.

S1-18 Code Review Exercise 1 hr

Review a multi-language codebase for security vulnerabilities. Document findings using the structured report format. Score against the expected finding list.

S1-19 Threat Modeling Exercise 0.5 hr

Produce a threat model for a given system architecture. Score against the expected threat list and mitigation recommendations.

Exam

Practical Certification Exam

S1-20 Practical Exam: Find, Fix and Verify 4 hrs

Four-hour practical exam. You receive a codebase with vulnerabilities spanning all 17 ASVS chapters. Find each vulnerability, fix it, and verify the fix against the ASVS requirement. Open-book (ASVS, Prompt Pack, and course materials allowed). AI assistants permitted but you must verify the output. Passing score: 70%. Graded by the instructor.

S1-21 Exam Debrief and Certification 0.5 hr

Walk through the exam findings as a group. Discuss the vulnerabilities, the fixes, and the verification approach. Candidates who pass receive the CyberSecAI Certified Secure Developer credential.

~40 hrs
Total instructional hours
28
Individual modules
3 days + exam
Delivery days
Reserve a place

Earn the Certified Secure Developer credential.

Three days covering all 17 ASVS 5.0 chapters, followed by a four-hour practical exam. Open-book, AI-assisted, graded by the instructor. CyberSecAI Certified Secure Developer credential on passing.

3 days + 4-hour exam 17 chapters full ASVS coverage Credential on passing
Reserve a Place

Corporate and sovereign cohorts, and bespoke on-site delivery, on request.