Secure Software Delivery: From Code to Deployment is an intermediate-level course designed to help developers and technical leads build and ship secure applications confidently—without slowing down innovation. As software systems scale, so do the risks—and success now depends on embedding security into every phase of the development lifecycle. In this course, you’ll move beyond one-off vulnerability patching and learn how to systematically integrate secure coding practices, threat modeling, and automated security testing into your workflows.
Through engaging videos, real-world case studies, interactive labs, and scenario-based coaching, you’ll gain hands-on experience with tools like SAST, DAST, and GitHub Actions. Whether you're fixing critical flaws, shifting security left in CI/CD, or leading team-wide secure coding habits, this course will help you operationalize security as a continuous, collaborative practice—and deliver software that’s not just functional, but resilient.
In this first lesson, learners discover why spotting and ranking security risks early is essential to build secure, cloud-based applications. Developers and security teams move from reacting to vulnerabilities to anticipating them. Using frameworks such as STRIDE and DREAD, learners practice mapping high-priority threats before any code ships. The Equifax breach In this first lesson, learners discover why spotting and ranking security risks early is essential to build secure, cloud-based applications.
Developers and security teams move from reacting to vulnerabilities to anticipating them. Using frameworks such as STRIDE and DREAD, learners practice mapping high-priority threats before any code ships. The Equifax breach illustrates the real-world cost of poor risk prioritization—and the value of getting it right. Videos, hands-on threat-modeling exercises, and guided discussions grow the risk awareness and strategic thinking needed to embed security measures into the development process from the start.exercises, and guided discussions grow the risk awareness and strategic thinking needed to embed security measures into the development process from the start.
涵盖的内容
3个视频3篇阅读材料1个作业
显示有关单元内容的信息
3个视频•总计11分钟
Introduction and Welcome•3分钟
Why Threat Modeling Matters—A Shift in Perspective•3分钟
Learning from Equifax—Prioritizing Risks in Practice•5分钟
3篇阅读材料•总计15分钟
Welcome to the Course: Course Overview•5分钟
Threat Modeling: STRIDE and DREAD Frameworks•5分钟
Real-World Threat Modeling Success Stories•5分钟
1个作业•总计10分钟
HOL: Creating Your First Threat Model•10分钟
Lesson 2: Remediate OWASP Top-10 with Secure Coding & Tools
第 2 单元•小时 后完成
单元详情
In this lesson, learners will explore the OWASP Top-10 vulnerabilities and how to prevent security incidents through proactive secure coding practices and effective analysis tools. The lesson emphasizes why fixing security flaws late in the process is costly and unsustainable, and how systematic prevention—through secure coding and regular testing—offers a better approach.
Real-world security incidents, such as the Fortnite XSS vulnerability, are highlighted to illustrate the practical consequences of common coding mistakes. Learners will be introduced to essential tools including Static Application Security Testing (SAST) and dynamic scanning with OWASP ZAP. Through a blend of videos, readings, discussions, and hands-on labs, learners will gain the skills and confidence to systematically build secure, robust applications—transforming their coding approach from reactive fixes to proactive prevention.
涵盖的内容
2个视频2篇阅读材料1个作业
显示有关单元内容的信息
2个视频•总计10分钟
Why the OWASP Top-10 Changes How You Code•5分钟
Avoiding the Pitfalls: Real Stories of Vulnerabilities•5分钟
2篇阅读材料•总计11分钟
Building Security Into Every Line: A Developer’s Guide to Safer Code•6分钟
Real-World Lessons: Case Studies in Secure Coding•5分钟
1个作业•总计10分钟
HOL: Use SAST Scans to Identify and Remediate OWASP Top-10 issues•10分钟
Lesson 3: Securing Builds with CI/CD Checks
第 3 单元•小时 后完成
单元详情
In this lesson, learners examine how embedding security into Continuous Integration and Continuous Deployment (CI/CD) pipelines transforms release processes into continuous guardians of trust rather than mere delivery engines. Through a scenario illustrating a late-night deployment where a known vulnerable library slipped into production, the lesson highlights why automated security checks must be integrated from the very first pipeline stage.
Learners will investigate practical tool implementations—such as Snyk for dependency scanning, OWASP Dependency-Check for open-source vulnerability detection, and GitHub Actions workflows for automation—to ensure issues are caught before code reaches production. Case studies of CI/CD misconfigurations, such as the Capital One cloud breach, demonstrate how small oversights in pipeline or infrastructure-as-code settings can lead to major incidents, reinforcing the need for continuous oversight.
Hands-on demonstrations guide learners through setting up security gates that fail builds on critical findings, interpreting scan results, and configuring policy-as-code enforcement, all without impeding development velocity. By the end of the lesson, participants will understand both how to configure and integrate these security tools into real pipelines and why treating security as a separate stage is no longer acceptable—security must be continuous, integrated, and owned by every stakeholder in the delivery workflow.
涵盖的内容
3个视频2篇阅读材料3个作业
显示有关单元内容的信息
3个视频•总计12分钟
Why Security Belongs in Every Build•5分钟
How Automated Security Gates Protect Your Pipeline•5分钟
Congratulations and Continuous Learning Journey•1分钟
2篇阅读材料•总计16分钟
Essential CI/CD Security Tools and Patterns•6分钟
Understanding the Capital One Cloud Misconfiguration Breach•10分钟
3个作业•总计56分钟
HOL: Scan and Secure a Sample Pipeline•6分钟
Project: Create Your Secure Development & Deployment Blueprint•40分钟
Coursera brings together a diverse network of subject matter experts who have demonstrated their expertise through professional industry experience or strong academic backgrounds. These instructors design and teach courses that make practical, career-relevant skills accessible to learners worldwide.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.