Open Authentication (OAuth) Training Course
Open Authorization (OAuth) is an open technology standard utilized for web-based authentication. It outlines the process by which independent servers and services can safely grant authenticated access to resources without the need to share user credentials.
This instructor-led, live training session (available online or on-site) is designed for developers and professionals looking to master OAuth to enable secure, delegated access for their applications.
Upon completion of this training, participants will be capable of:
- Gaining a solid understanding of OAuth fundamentals.
- Comprehending the unique security challenges associated with native applications when implementing OAuth.
- Learning about and understanding common extensions to the OAuth protocol.
- Integrating with any OAuth authorization server.
Course Format
- Interactive lectures and group discussions.
- Extensive exercises and practical practice.
- Hands-on implementation within a live-lab environment.
Course Customization Options
- To request a customized training version of this course, please contact us to arrange.
Course Outline
Introduction
- Overview of OAuth
- Understanding API security
OAuth
- Protocol endpoints
- Scope
- Authorization code for web apps
- Implicit flow for single-page apps
- Client credentials for machines
- Resource owner password credentials
- Long-lived access with refresh tokens
- Choosing the right response mode
- Simplifying OAuth with OAuth 2.1
Native Applications Best Practices
- Unique issues of native apps
- Using PKCE to handle stolen tokens
- Choosing the best redirect URI
Browser-based Application Best Practices
- The security profile of the browser-based app
- OAuth within the browser
- Avoiding OAuth with SameSite cookies
- Securing browser-based apps with backend for frontend
Extending OAuth
- OAuth and Identity with OpenID Connect
- Configuring clients with OAuth metadata
- Authorizing the IoT with the OAuth device flow
- Combining SAML and OAuth with the SAML assertion grant
- Securing Microservices with token exchange
Summary and Next Steps
Requirements
- Basic knowledge of web service and API development
Audience
- Developers
Open Training Courses require 5+ participants.
Open Authentication (OAuth) Training Course - Booking
Open Authentication (OAuth) Training Course - Enquiry
Open Authentication (OAuth) - Consultancy Enquiry
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
The way to receive the information from the trainer
Mohamed Romdhani - Shams Power
Course - CISM - Certified Information Security Manager
Upcoming Courses
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) is designed for IT auditors at an intermediate level who wish to effectively incorporate AI tools into their audit practices.
By the end of this training, participants will be able to:
- Grasp the core concepts of artificial intelligence and how it is applied in the context of IT auditing.
- Utilize AI technologies such as machine learning, NLP, and RPA to improve audit efficiency, accuracy, and scope.
- Perform risk assessments using AI tools, enabling continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, enhancing the overall effectiveness of IT audits.
Micro Focus ArcSight ESM Advanced
35 HoursThis instructor-led, live training in Czech Republic (online or onsite) targets advanced-level security analysts seeking to elevate their skills in utilizing advanced Micro Focus ArcSight ESM content. This training aims to improve an organization’s ability to detect, respond to, and mitigate cyber threats with greater precision and speed.
By the end of this training, participants will be able to:
- Optimize Micro Focus ArcSight ESM to enhance monitoring and threat detection capabilities.
- Construct and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules for effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
CCTV Security
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) is tailored for security managers who wish to develop basic to intermediate-level skills in CCTV security surveillance and management.
By the conclusion of this training, participants will be able to:
- Familiarize themselves with different types of CCTV systems and recognize their benefits and features.
- Understand the cabling and setup requirements for CCTV systems.
- Install, configure, and manage CCTV systems.
Certified Fraud Examiner (CFE) Preparation
70 HoursThis instructor-led, live training in Czech Republic (online or on-site) is designed for advanced-level professionals who wish to gain a comprehensive understanding of fraud examination concepts and prepare for the Certified Fraud Examiner (CFE) exam.
Upon completing this training, participants will be able to:
- Acquire a thorough understanding of fraud examination principles and the examination process.
- Learn to identify, investigate, and prevent various forms of financial fraud schemes.
- Understand the legal framework surrounding fraud, including its legal elements, relevant laws, and regulations.
- Gain practical skills in conducting fraud investigations, such as evidence collection, interviewing techniques, and data analysis.
- Learn to design and implement effective fraud prevention and deterrence programs within organizations.
- Build the confidence and knowledge necessary to successfully pass the Certified Fraud Examiner (CFE) exam.
CGEIT – Certified in the Governance of Enterprise IT
28 HoursDescription:
This four-day event, comprising CGEIT training, serves as the ultimate preparation for the examination phase. It is specifically designed to ensure that you successfully pass the challenging CGEIT exam on your first attempt.
The CGEIT qualification is an internationally recognized symbol of excellence in IT governance, awarded by ISACA. It is tailored for professionals who are responsible for managing IT governance or who hold significant advisory or assurance responsibilities within this domain.
Achieving CGEIT status will enhance your market recognition and increase your influence at the executive level.
Objectives:
This seminar has been designed to prepare delegates for the CGEIT examination by enabling them to supplement their existing knowledge and understanding, ensuring they are better prepared to pass the exam as defined by ISACA.
Target Audience:
Our training course is intended for IT and business professionals with significant IT governance experience who are undertaking the CGEIT exam.
CipherTrust Manager
21 HoursThis instructor-led, live training in Czech Republic (online or onsite) is aimed at IT professionals who wish to understand how to use the CipherTrust Solution suite.
By the end of this training, participants will be able to:
- Understand the CipherTrust Solution and its basic functions.
- Evaluate device architecture and usage schemes.
- Manage CipherTrust product suite.
CISM - Certified Information Security Manager
28 HoursDescription:
Please note that this updated CISM exam content outline applies to exams beginning on 1 June 2022.
CISM® stands as the most prestigious and rigorous qualification for Information Security Managers worldwide. This certification offers a pathway to join an elite network of peers who are equipped to continuously learn and adapt to the expanding opportunities and challenges within Information Security Management.
Our CISM training methodology delivers comprehensive coverage of the four CISM domains, with a strong emphasis on building conceptual understanding and solving ISACA-published CISM exam questions. The course serves as intensive, rigorous exam preparation for ISACA’s Certified Information Security Manager (CISM®) Examination.
Our instructors advise all participants to review the ISACA-published CISM QA&E (Questions, Answers, and Explanations) as part of their exam preparation. The QA&E is particularly valuable in helping participants grasp the ISACA question format, the approach to answering them, and facilitates rapid assimilation of CISM concepts during live classroom sessions.
All our trainers possess extensive experience in delivering CISM training. We will thoroughly prepare you for the CISM examination.
Goal:
The primary objective is for you to pass your CISM examination on the first attempt.
Objectives:
- Apply the acquired knowledge in a practical manner that benefits your organization
- Establish and maintain an information security governance framework to achieve organizational goals and objectives
- Manage information risk to an acceptable level to satisfy business and compliance requirements
- Establish and maintain information security architectures (people, process, technology)
- Integrate information security requirements into the contracts and activities of third parties and suppliers
- Plan, establish, and manage the capability to detect, investigate, respond to, and recover from information security incidents to minimize business impact
Target Audience:
- Security professionals with 3-5 years of frontline experience
- Information security managers or individuals with management responsibilities
- Information security staff and assurance providers who require a deep understanding of information security management, including: CISOs, CIOs, CSOs, privacy officers, risk managers, security auditors, compliance personnel, BCP/DR personnel, and executive or operational managers responsible for assurance functions
Compliance for Payment Services in Japan
7 HoursThis instructor-led, live training in Czech Republic (online or onsite) is designed for compliance professionals in the payment services sector who wish to create, implement, and enforce a compliance program within an organization.
By the end of this training, participants will be able to:
- Understand the rules set forth by government regulators for payment service providers.
- Create the internal policies and procedures needed to satisfy government regulations.
- Implement a compliance program that adheres to relevant laws.
- Ensures that all corporate processes and procedures comply with the compliance program.
- Uphold the business's reputation while protecting it from lawsuits.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) targets intermediate-level cybersecurity professionals aiming to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers an expert introduction to the newly enacted Accessibility Law, equipping developers with the practical skills necessary to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's importance and implications, the course rapidly transitions to hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
HiTrust Common Security Framework Compliance
14 HoursThis instructor-led, live training in Czech Republic (online or onsite) is aimed at developers and administrators who wish to produce software and products that are HiTRUST compliant.
By the end of this training, participants will be able to:
- Understand the key concepts of the HiTrust CSF (Common Security Framework).
- Identify the HITRUST CSF administrative and security control domains.
- Learn about the different types of HiTrust assessments and scoring.
- Understand the certification process and requirements for HiTrust compliance.
- Know the best practices and tips for adopting the HiTrust approach.
ISO 27002 Lead Manager
35 HoursThe PECB ISO/IEC 27002 Lead Manager training program equips you with the essential expertise and knowledge required to assist an organization in implementing and managing Information Security controls in accordance with ISO/IEC 27002.
Upon successful completion of this course, you will be eligible to take the exam and apply for the "PECB Certified ISO/IEC 27002 Lead Manager" credential. This PECB Lead Manager Certification validates your mastery of the principles and techniques necessary for the implementation and management of Information Security Controls based on ISO/IEC 27002.
Who should attend?
- Managers or consultants aiming to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 and ISO/IEC 27002
- Project managers or consultants seeking to master the implementation process of an Information Security Management System
- Individuals responsible for information security, compliance, risk, and governance within an organization
- Members of information security teams
- Expert advisors in information technology
- Information Security officers
- Privacy officers
- IT professionals
- CTOs, CIOs, and CISOs
Learning objectives
- Master the implementation of Information Security controls by adhering to the framework and principles of ISO/IEC 27002
- Gain a comprehensive understanding of the concepts, approaches, standards, methods, and techniques required for the effective implementation and management of Information Security controls
- Comprehend the relationship between the components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance, and human behavior
- Understand the importance of information security for organizational strategy
- Master the implementation of information security management processes
- Master the formulation and implementation of security requirements and objectives
Educational approach
- This training integrates both theory and practice
- Lecture sessions illustrated with examples based on real-world cases
- Practical exercises based on case studies
- Review exercises designed to assist with exam preparation
- Practice tests similar to the certification exam
General Information
- Certification fees are included in the exam price
- Training material containing over 500 pages of information and practical examples will be distributed to participants
- A participation certificate granting 31 CPD (Continuing Professional Development) credits will be issued to participants
- In the event of an exam failure, you may retake the exam within 12 months free of charge
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This course is designed for all employees seeking a practical grasp of Compliance and effective Risk Management.
Course Format
The training utilizes a blended methodology that encompasses:
- Guided discussions
- Slide-driven presentations
- Case studies
- Practical real-world examples
Course Objectives
Upon completion, participants will be equipped to:
Gain a robust understanding of key Compliance principles, alongside national and international initiatives focused on managing related risks.
Articulate how organizations and their teams can implement an effective Compliance Risk Management Framework.
Outline the responsibilities of the Compliance Officer and the Money Laundering Reporting Officer, and understand how these roles fit within a business structure.
Pinpoint critical risk areas within Financial Crime, particularly concerning international operations, offshore centers, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves supervising the lifecycle of open-source components within an organization to guarantee secure, compliant, and efficient utilization.
This instructor-led, live training (available online or onsite) targets intermediate-level IT professionals looking to apply best practices for managing open-source software in enterprise and government settings.
Upon completing this training, participants will be capable of:
- Developing effective OSS policies and governance frameworks.
- Utilizing SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Reducing risks linked to licensing and security vulnerabilities.
- Optimizing OSS adoption to enhance innovation and reduce costs.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Practical demonstrations with OSS management tools.
Customization Options
- The course can be tailored to fit specific organizational OSS policies and toolchains. Please contact us to arrange this.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Czech Republic (online or onsite) grants an individual qualification to industry practitioners seeking to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).
Upon completion of this training, participants will be able to:
- Comprehend the payment process and the PCI standards established to protect it.
- Understand the roles and responsibilities of entities involved in the payment industry.
- Gain deep insight into and understanding of the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and its application to organizations involved in the transaction process.