The ISO/IEC 27034 Foundation training course provides participants with an understanding of the fundamental principles of application security and the requirements of ISO/IEC 27034. The course covers key domains, including the concepts and scope of application security, as well as organizational and application-level planning, application security controls, and monitoring of security controls.
Participants will also learn how to verify and align application security practices with organizational objectives and regulatory requirements, including how to tailor an Application Normative Framework (ANF) to define the necessary security controls and processes that help each application meet its Targeted Level of Trust (TLT).
Why Should You Attend?
The ISO/IEC 27034 Foundation training course enables participants to understand the fundamental concepts and principles of application security, as well as the structure, components, and requirements of ISO/IEC 27034. This course is designed to prepare professionals to support the implementation and maintenance of application security throughout the software life cycle.
By attending this course, participants will learn how ISO/IEC 27034 aligns with other standards, understand key security principles such as confidentiality, integrity, and availability, and gain insight into the roles involved in managing the Organization Normative Framework (ONF) and Application Normative Framework (ANF).
Learning Objectives
By the end of this training course, participants will be able to:
- Describe the structure, scope, and components of the ISO/IEC 27034 series and understand how it aligns with and complements other standards and frameworks
- Identify and explain key concepts and principles such as confidentiality, integrity, availability, threats, vulnerabilities, and risks, and understand their relevance in securing applications throughout their life cycle
- Explain the roles and responsibilities in establishing and maintaining the Organization Normative Framework (ONF) and Application Normative Framework (ANF)
- Describe the processes for validating application security requirements, assessing security risks, verifying security controls, and using KPIs to support continual improvement of application security practices
Educational Approach
- This training course includes essay-type exercises and multiple-choice quizzes, helping participants understand application security concepts and processes.
- Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions during the training.
- The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared.
- PECB offers various training course delivery formats, from traditional classroom settings to modern, technology-driven solutions. To learn more about these formats, please clickĀ here.
Prerequisites
There are no prerequisites to participate in this training course.
Who Should Attend
Schedule Dates
Course Content
- Introduction to application security and ISO/IEC 27034
FAQs
This course introduces participants to the principles and practices of securing applications throughout their lifecycle, based on the ISO/IEC 27034 standard. It provides foundational knowledge for integrating security into software development and application management processes.
Flexible Training Options to Meet Your Needs
We know the importance of flexibility in the success of learning and professional development. This is the reason CounselTrain provides a variety of delivery options for all IT training offered in the UAE to ensure access and convenience for each learner.
Online Instructor-Led Training
Learn from the comfort of your workplace or at home through live virtual sessions led by expert trainers.