I am trying to establish an application security group within an organization and although there is a plethora of courses for penetration testers, i fail to find an equal amount of training courses for developers / QA testers
The team i work with is very capable when it comes to its core functions (development, testing, testing automation) but have very limited exposure to application security - very basic knowledge of the OWASP Top 10
I looked on the Internet for courses to help them build their knowledge, and so far i have found 2-3 courses from SANS and a training bundle from Aspect Security. I haven't tried any of these yet, since i wanted to get some opinions before we commit
The ideal course(s) should contain:
- An introduction, ideally based on the OWASP Top 10
- Defensive techniques, ideally presented as a framework (e.g. OWASP ESAPI)
- Security testing, oriented towards QA testers who like to automate vs manual penetration testing
- Application of WAFs (for virtual patching)
Do you know of any course bundle that can provide me with this content, or should i be looking for individual courses from different providers? And if so, can you provide me with the names of training providers that you have used and you are satisfied with?