華睿教育
返回課程列表

資訊安全

ISO/IEC 27034 — Application Security

課程類型、時長及學費

課程類型適合對象企業得益時長學費
Foundation希望學習管理系統及其流程實施基礎的人士透過理解 ISO 標準的核心要素,為機構建立以最佳實務為本的取向與文化2 HKD 4,400
Lead Implementer負責在公司實施及管理管理系統的人員由具備能力的人員帶領推行最佳實務,改善整體流程,邁向符合 ISO 標準5 HKD 11,200
Lead Auditor負責在公司審核及監察管理系統的人員由具備能力的人員審核流程,確保管理系統妥善實施,邁向成功合規與認證5 HKD 11,200

About the standard

ISO/IEC 27034 helps organizations embed security practices throughout the application lifecycle, from development and operation through to maintenance. It introduces the Application Security Life Cycle (ASLC) model and the Organization Normative Framework (ONF), a centralized repository for security practices that lets organizations tailor their controls to specific goals and regulatory requirements. The standard is published in several parts, covering overview and concepts, the ONF, the application security management process, control data structures, case studies, and an assurance prediction framework.

Levels available

  • Application Security Foundation — Introduces the core concepts of ISO/IEC 27034, including the ASLC model and the ONF, giving learners a solid grounding in application security.
  • Lead Application Security Implementer — For those responsible for implementing application security controls, covering the skills to embed and manage security across the application lifecycle.
  • Lead Application Security Auditor — For those responsible for auditing application security practices, developing the competence to assess conformity with the standard.

Who should attend

This course track is for application security engineers, software architects, and DevSecOps professionals responsible for building security into applications. It's also relevant to security managers and auditors who need to assess or oversee application security practices across an organization.

Learning objectives

  • Understand the application security principles set out in ISO/IEC 27034
  • Learn to implement and manage security controls throughout the application lifecycle
  • Gain proficiency applying application security controls using the ASLC model
  • Understand how to use the ONF to align security practices with organizational goals and regulatory requirements
  • Learn to develop, validate, and oversee application security controls and integrate them with existing security processes

Why attend

As applications increasingly handle sensitive data and critical operations, application security has become a top priority for organizations of every size. This training builds the structured, lifecycle-based skills to reduce vulnerabilities before they can be exploited, demonstrates competence in managing application security effectively, and builds trust with clients and stakeholders through an internationally recognized credential.

PECB link

https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27034

PECB 官方頁面