Application Security Testing is a key component of any organization’s software assurance program. The importance of these practices is reflected by their presence throughout OWASP's Software Assurance Maturity Model (SAMM), where they're represented primarily by two of the model's 15 core Practices (Requirement-driven Testing and Security Testing), and factor into numerous activities across the remaining Practices. This class covers recommended Application Security Testing (AST) practices, along with supporting AST tools and ways to better leverage penetration testing, to verify and validate an application’s security features: * Verify – How do we confirm our application’s security features were built right? * Validate – How do we confirm we built the right security features, to secure the application's functionality? Topic coverage will include establishing your overall AST strategy and aligning it with the OWASP ASVS (Application Security Verification Standard); defining and implementing security tests cases; leveraging AST tools; and using third-party penetration tests effectively within your testing strategy.