Security Fundamentals and Threat Modeling
Learn the security fundamentals every engineer needs: the CIA triad, OWASP Top 10, encryption and TLS, and threat modeling with STRIDE.
What You'll Learn
Understanding Why Security Is Every Engineer's Job
A small payments startup in Pune shipped a feature on a Thursday. One API endpoint returned a user's profile by ID: GET /api/users/1042.
Understanding the CIA Triad and Access Control
Before you can protect a system, you need words for what "protected" means.
Understanding the OWASP Top 10
The OWASP Top 10 is the security industry's most widely used awareness document.
Preventing Injection and Keeping Code Separate from Data
Injection has been near the top of every OWASP list for two decades because the underlying mistake is so easy to make: the application takes input...
Choosing Between Hashing and Encryption
"Encrypt it" is the advice people reach for whenever data feels sensitive, and half the time encryption is the wrong tool.
Securing Connections with TLS, Certificates, and PKI
Every time you see the padlock in a browser, hashing and both kinds of encryption are working together.
Skills You'll Master
Curriculum Index9 topics
Understanding Why Security Is Every Engineer's Job
A small payments startup in Pune shipped a feature on a Thursday.
Understanding the CIA Triad and Access Control
Before you can protect a system, you need words for what "protected" means.
Understanding the OWASP Top 10
The OWASP Top 10 is the security industry's most widely used awareness document.
Preventing Injection and Keeping Code Separate from Data
Injection has been near the top of every OWASP list for two decades because the underlying mistake is so easy to make...
Choosing Between Hashing and Encryption
"Encrypt it" is the advice people reach for whenever data feels sensitive, and half the time encryption is the wrong...
Securing Connections with TLS, Certificates, and PKI
Every time you see the padlock in a browser, hashing and both kinds of encryption are working together.
Understanding Threat Modeling with STRIDE
Everything so far has been about known categories of risk.
Running the Lab: Exploiting and Threat Modeling an App
In this lab you will do both halves of this module's work.
Reviewing Security Fundamentals: Quick Reference and Common Mistakes
Quick reference Common mistakes Confusing authentication with authorization.
Career Impact
Roles that use the skills in this module.
DevSecOps Engineer
Platform Engineer
Cloud Engineer
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
No. This module is for any engineer who builds or runs software. It teaches the shared vocabulary (CIA, OWASP, STRIDE) and the few ideas you use every day, so you can reason about risk and talk to security teams without memorising a certification syllabus.
No, and OWASP says so directly. It is an awareness document of the most common risk categories, not a complete test. Use it to learn the usual ways apps get attacked, then rely on threat modeling and testing to find what is specific to your system.
Authentication proves who you are, like showing an ID at a door. Authorization decides what you are allowed to do once you are inside, like which rooms your key card opens. Most access-control bugs come from getting authorization wrong, not authentication.
Not to use it safely. You need to know when to use hashing versus encryption, when to use symmetric versus asymmetric, and never to invent your own scheme. The maths matters for people who design algorithms; your job is to use well-tested libraries correctly.