Technical Cybersecurity
This domain covers application security under ISO/IEC 27034 — the standard addressing how security is built into software rather than added afterwards. It is aimed at the people closest to the code and the systems: developers, application security specialists, and the auditors who assess whether an organization’s development practice genuinely produces secure software.
Courses
3
Standards
1
Languages
1
From
€390
Who this is for
- Application security engineers and security champions
- Software developers and architects with security responsibility
- Auditors assessing secure development practice
- Security managers overseeing an application security programme
Standards in this category
Credential levels available
Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →
All technical cybersecurity courses€390–€750
Frequently asked questions
What does ISO/IEC 27034 cover?
ISO/IEC 27034 addresses application security as an organizational process — defining how security requirements are determined, how controls are selected and verified across the application lifecycle, and how an organization demonstrates that its applications reach a defined level of trust. It concerns process and governance rather than a checklist of specific vulnerabilities.
How is this different from the Information Security category?
Information security standards such as ISO/IEC 27001 address the organization’s overall management of security. ISO/IEC 27034 goes narrow and deep on one part of it — the software the organization builds or acquires. Professionals commonly hold credentials in both.
Should I take the Implementer or the Auditor course?
Lead Application Security Implementer if you will establish secure development practice within an organization. Lead Application Security Auditor if you will assess it — as an internal auditor, consultant, or on behalf of a certification body.
Do I need to be able to write code?
Coding ability is not required. The material addresses process, control selection and verification rather than programming, though familiarity with how software is built and released makes it considerably more concrete.