
ISO/IEC 27034 Application Security Foundation
Course Overview
Modern applications are critical to business operations but are increasingly exposed to cyber threats and vulnerabilities. The ISO/IEC 27034 Application Security Foundation course introduces participants to internationally recognized guidance for embedding security into every stage of the application lifecycle.
Participants will gain an understanding of the Application Security Framework (ASF), the Organization Normative Framework (ONF), the Application Normative Framework (ANF), and Application Security Controls (ASCs). The course also covers secure software development practices, application risk management, and security verification techniques to support the development of resilient and secure applications.
Target Audience
This course is intended for:
- Individuals seeking a foundational understanding of application security
- Software developers and application engineers
- Secure software development teams
- Information security professionals
- IT managers and solution architects
- Cybersecurity professionals
- Risk management professionals
- Internal auditors
- Security consultants
- Anyone interested in application security and ISO/IEC 27034
Learning Objectives
Upon successful completion of this course, participants will be able to:
- Understand the purpose, scope, and benefits of ISO/IEC 27034.
- Explain the key principles of application security.
- Describe the ISO/IEC 27034 Application Security Framework (ASF).
- Understand the Organization Normative Framework (ONF) and the Application Normative Framework (ANF).
- Identify and apply Application Security Controls (ASCs).
- Recognize common application security threats and vulnerabilities.
- Understand secure software development lifecycle (SSDLC) concepts.
- Explain application security testing and verification methods.
- Prepare for the PECB ISO/IEC 27034 Application Security Foundation certification examination.
Duration
2 Days (Approximately 14–16 hours of instructor-led training)
Classroom
Participants attend instructor-led classroom sessions that encourage interactive learning, practical discussions, and collaboration with experienced instructors and fellow participants.
Certification
Participants who successfully pass the examination will receive the:
PECB Certified ISO/IEC 27034 Application Security Foundation
The certification validates the candidate’s understanding of the fundamental concepts, principles, and best practices for application security based on ISO/IEC 27034.
Course Agenda
Day 1: Introduction to ISO/IEC 27034 and Application Security Fundamentals
- Training course objectives and structure
- Overview of ISO/IEC 27034
- Application security concepts and terminology
- Application Security Framework (ASF)
- Organization Normative Framework (ONF)
- Application lifecycle security
- Roles and responsibilities
Day 2: Application Security Controls and Certification Exam
- Application Normative Framework (ANF)
- Application Security Controls (ASCs)
- Secure Software Development Lifecycle (SSDLC)
- Application security risk management
- Security verification and testing
- Continual improvement
- Course review
- PECB ISO/IEC 27034 Application Security Foundation Certification Examination
Exam Duration
- Exam Duration: 1 hour (60 minutes)
- Exam Format: Closed-book, multiple-choice examination.
- Passing Score: Determined by PECB in accordance with its certification policies.
Successful candidates who pass the examination may apply for the PECB Certified ISO/IEC 27034 Application Security Foundation credential, subject to PECB’s certification requirements.
