WEEK 10

Software & Secure Development Lifecycle

Operational scenario

A vendor library in the fictional company's customer portal has a critical CVE. Find it, fix it and prove it's fixed.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 9; acronym quiz 5
Deliverable: Threat model + SBOM
Learning objectives
  • Apply SDLC / SSDLC
  • Threat model
  • Use OWASP Top 10 (2025)
  • Manage SBOM & supply-chain risk
Classroom topics
  • Threat modeling
  • Secure coding
  • SAST / DAST / SCA
  • Secrets & API security
  • CI/CD & DevSecOps
  • SBOM & open-source risk
Standards · vocabulary
NIST SSDF (SP 800-218)OWASP Top 10 2025
SDLCSSDLCSBOMSASTDASTSCA
Open glossary
Competency demonstrated: Applies secure-development practices.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Generate an SBOM for a sample app; review dependencies.

~2 h
Docker container lab

Lab 8 revisit — exploit, then patch a vulnerable web app (OWASP).

~0.5 h
AR/VR immersive scenario

Desktop-first: walk a CI/CD pipeline's trust boundaries. Role: Governance and compliance analyst.

No headset? Desktop pipeline diagram task. Printed and mobile versions are also available.

Individual technical assignment

Threat-model a small app (data-flow diagram).

Team exercise

Fix three OWASP Top 10 issues in a sample codebase.

Required hardware
  • Workstation
Required software
  • OWASP Juice Shop
  • SCA tool (e.g., Syft/Grype)
  • Code editor
Workplace application

SBOMs are now requested in federal procurement and many vendor contracts.

Docker progression step
L8 Identifying an intentionally vulnerable web application

Fingerprint webapp; list three candidate weaknesses with CWE IDs. Week 10: patch and re-test.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Vulnerability & patch managementSecure software developmentSupply-chain & third-party risk
See the full crosswalk