WEEK 10
Software & Secure Development Lifecycle
Operational scenario
A vendor library in the fictional company's customer portal has a critical CVE. Find it, fix it and prove it's fixed.
Week completion
0%
~10 hours this week
Assessment: Knowledge check 9; acronym quiz 5
Deliverable: Threat model + SBOM
Learning objectives
- Apply SDLC / SSDLC
- Threat model
- Use OWASP Top 10 (2025)
- Manage SBOM & supply-chain risk
Classroom topics
- Threat modeling
- Secure coding
- SAST / DAST / SCA
- Secrets & API security
- CI/CD & DevSecOps
- SBOM & open-source risk
Standards · vocabulary
NIST SSDF (SP 800-218)OWASP Top 10 2025
SDLCSSDLCSBOMSASTDASTSCA
Open glossaryCompetency demonstrated: Applies secure-development practices.
Four-mode learning matrix
~1.5 h
Physical hands-on lab
Generate an SBOM for a sample app; review dependencies.
~2 h
Docker container lab
Lab 8 revisit — exploit, then patch a vulnerable web app (OWASP).
~0.5 h
AR/VR immersive scenario
Desktop-first: walk a CI/CD pipeline's trust boundaries. Role: Governance and compliance analyst.
No headset? Desktop pipeline diagram task. Printed and mobile versions are also available.
Individual technical assignment
Threat-model a small app (data-flow diagram).
Team exercise
Fix three OWASP Top 10 issues in a sample codebase.
Required hardware
- Workstation
Required software
- OWASP Juice Shop
- SCA tool (e.g., Syft/Grype)
- Code editor
Workplace application
SBOMs are now requested in federal procurement and many vendor contracts.
Docker progression step
L8 Identifying an intentionally vulnerable web application
Open the Docker rangeFingerprint webapp; list three candidate weaknesses with CWE IDs. Week 10: patch and re-test.
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Vulnerability & patch managementSecure software developmentSupply-chain & third-party risk
See the full crosswalkReflection & rubric for week 10 Modes tracked: 0/5