Professional IT services from accompio for companies in Germany.
Training

Fortify

Implementing application security in practice: Detect, analyse and systematically fix vulnerabilities with Fortify.

This training is aimed at the entire DevSecOps team. The workshop will cover the fundamentals of application security, whether through static code analysis or automated penetration testing.

Application Security with Micro Focus Fortify

Who is the training suitable for?

This training is aimed at the entire DevSecOps team – whether you are a developer, security auditor, or project manager who is interested in application security.

Duration
3 days (8h/day)
Format
In-house or with accompio
Number of participants
on request
Target group
The entire DevSecOps team – whether developers, security auditors, or project managers.
Test encryption and security with Apache JMeter.

Fortify Training – Secure Application Development

This training is aimed at the entire DevSecOps team – from developers and security auditors to project managers. It provides practical, hands-on instruction on the fundamentals of modern application security and demonstrates how security checks can be systematically integrated into development and quality assurance processes. Based on the OWASP Top 10, participants will develop a sound understanding of typical attack scenarios such as SQL injection or cross-site scripting. They will learn the architecture and functions of Fortify and implement static code analyses with Fortify Static Code Analyzer, as well as dynamic tests with Fortify WebInspect. Integration into build and CI environments, along with professional auditing and evaluation of results, round off the practical training.

Contents at a glance

  • Improving the Security of Your Applications with Fortify Static Code Analyzer and Fortify WebInspect
  • Fundamentals in handling the individual tools
  • Best practices, as well as tips and tricks, for working with the tools

  • Integration of Fortify into build management tools Apache Maven, Gradle or Ant
  • Connection to a continuous integration software such as Jenkins

  • Scanning of various languages (Java, C/C++, .NET, etc.)
  • Using different utilities (command line, Audit Workbench, IDE plugins)
  • Scanning of websites and web applications
  • Scanning REST and SOAP interfaces
  • Creating scripts for automation

  • Detecting and filtering false positives
  • Create a report
  • In-depth analysis of the issues

Your added value

Strengthen security awareness

Understand typical attack scenarios and security risks from an attacker's perspective.

Apply static and dynamic analysis

Identify vulnerabilities early with Fortify Static Code Analyzer and WebInspect.

Integration in CI/CD processes

Seamlessly integrate security checks into build and continuous integration environments.

Assessing false positives reliably

Learn to professionally review analysis results and create well-founded reports.

Broad technology coverage

Scan different programming languages, as well as web and API interfaces.

Best practices for DevSecOps

Woman with a headset in customer service at Accompio IT Services.

Get in touch with us

We at accompio will be happy to help you.