CURRICULUM: Cloud Security SEC522: Application Security: Securing Web Applications, APIs, and Microservices™ 5 Day Program You Will Be Able To ▐ Defend against OWASP Top 10 attacks and input- driven vulnerabilities like SQL injection, XSS, and CSRF ▐ Harden infrastructure, configurations, and software supply chains against modern attack campaigns ▐ Strengthen authentication and authorization with passkeys, multifactor authentication, OAuth, and SAML ▐ Protect REST and GraphQL APIs and microservices from abuse and data exposure ▐ Improve web security using protective HTTP headers, Content Security Policy, and cross-origin controls ▐ Secure AI and LLM-powered application components against prompt injection and other emerging attacks Who Should Attend ▐ Application developers ▐ Application security analysts or managers ▐ Application architects ▐ Penetration testers who are interested in learning about defensive strategies ▐ Security professionals who are interested in learning about web application security ▐ Auditors who need to understand defensive mechanisms in web applications ▐ Employees of PCI-compliant organizations who need to be trained to comply with those requirements NICE Framework Work Roles ▐ Software Developer (OPM 621) ▐ Secure Software Assessor (OPM 622) ▐ Research & Development Specialist (OPM 661) ▐ Information Systems Security Developer (OPM 631) ▐ Systems Developer (OPM 632) 30 CPEs 21 Labs GWEB giac.org/gweb Not a Matter of “If” but “When.” Be Prepared for a Web Attack. We’ll Teach You How. HTTP is no longer just about websites. It is the universal language that lets cloud services, microservices, APIs, and AI platforms talk to each other. Whether you are securing a traditional web application, protecting cloud-native services, or defending AI model endpoints, the fundamentals remain the same: HTTP-based protocols and the security implications that come with them. SEC522 is built around this reality and provides training that goes well beyond traditional web application security. As organizations move to cloud platforms, adopt microservices, and embed AI capabilities into their products, they are all building on the same HTTP foundation. A vulnerability in any of these systems can compromise far more than a single application. It can expose entire cloud environments, API ecosystems, and AI services. Business Takeaways ▐ ▐ Comply with PCI DSS requirements and other compliance requirements ▐ Reduce the overall application security risks, protect company reputation Adopt the “shift left” mindset: Address security issues early and quickly, reducing cost ▐ Adopt APIs, microservices, and AI capabilities in a secure manner ▐ Prepare students for the GWEB certification Syllabus Summary SECTION 1: Web Foundations and Secure Configurations SECTION 2: Input Attacks and Defenses SECTION 3: Authentication, Authorization, and Cryptography SECTION 4: APIs, Web Services, and Client-Side Security SECTION 5: AI Security, MLSecOps, and Microservices “ [Labs are] thought out and easy to follow with good practical knowledge learned.” —Barbara Boone, CDC “ Not only does SEC522 teach the defenses for securing web apps, it also shows how common and easy the attacks are and thus the need to secure the apps.” —Brandon Hardin, ITC For detailed course description, visit SANS.ORG/SEC522 Jason Lam Course Author Dr. Johannes Ullrich Course Author In-Person WAYS TO TAKE SEC522 Live Online OnDemand Web Application Defender