TDT4237 (progsik)
Software Security and Data Privacy
Spring
Trondheim
English
About this course
Content
The course will go through all the phases in the secure software development lifecycle (requirements, design, implementation, and testing) focusing on how to incorporate security in each phase and what techniques to use. The main focus is on web-based applications. The course will also cover basic knowledge related to data privacy, such as GDPR.
Learning outcomes
After having taken this course, students should be able to:
1) Identify and fix typical security vulnerabilities of web applications.
2) Explain typical cryptography concepts and algorithms that are related to web application;
3) Apply the threat modeling methods to analyze web application;
4) Describe and compare software engineering practices and standards related to software security;
5) Apply risk-based testing for development;
6) Explain key authentication and access control concepts and methods;
7) Explain and apply principles of GDPR and data privacy;
8) Critical evaluation and application of AI-assisted software security tools.
Teaching methods
Lectures and mandatory exercises.