Information Security
ISO/IEC 27034 — Application Security
Levels available
Course types, duration & fees
| Course type | Who should attend | What your company benefits | Duration | Fee |
|---|---|---|---|---|
| Foundation | Those who wish to learn the basis of implementing the management system and its processes | Provide the organization with best-practice based orientation and mindset culture by understanding the main important elements of ISO standards | 2 days | HKD 4,400 |
| Lead Implementer | Responsible persons for implementing and managing the management system in their company | Improve overall processes by implementing best practices led by competent staff that can lead to compliance with ISO standards | 5 days | HKD 11,200 |
| Lead Auditor | Responsible persons for auditing and monitoring management systems in their company | Ensure your management systems are implemented properly by having competent staff audit the processes that can lead to a successful compliance and certification | 5 days | HKD 11,200 |
About the standard
ISO/IEC 27034 helps organizations embed security practices throughout the application lifecycle, from development and operation through to maintenance. It introduces the Application Security Life Cycle (ASLC) model and the Organization Normative Framework (ONF), a centralized repository for security practices that lets organizations tailor their controls to specific goals and regulatory requirements. The standard is published in several parts, covering overview and concepts, the ONF, the application security management process, control data structures, case studies, and an assurance prediction framework.
Levels available
- Application Security Foundation — Introduces the core concepts of ISO/IEC 27034, including the ASLC model and the ONF, giving learners a solid grounding in application security.
- Lead Application Security Implementer — For those responsible for implementing application security controls, covering the skills to embed and manage security across the application lifecycle.
- Lead Application Security Auditor — For those responsible for auditing application security practices, developing the competence to assess conformity with the standard.
Who should attend
This course track is for application security engineers, software architects, and DevSecOps professionals responsible for building security into applications. It's also relevant to security managers and auditors who need to assess or oversee application security practices across an organization.
Learning objectives
- Understand the application security principles set out in ISO/IEC 27034
- Learn to implement and manage security controls throughout the application lifecycle
- Gain proficiency applying application security controls using the ASLC model
- Understand how to use the ONF to align security practices with organizational goals and regulatory requirements
- Learn to develop, validate, and oversee application security controls and integrate them with existing security processes
Why attend
As applications increasingly handle sensitive data and critical operations, application security has become a top priority for organizations of every size. This training builds the structured, lifecycle-based skills to reduce vulnerabilities before they can be exploited, demonstrates competence in managing application security effectively, and builds trust with clients and stakeholders through an internationally recognized credential.
PECB link
https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27034
