ISO/IEC 27034 Application Security Foundation

The ISO/IEC 27034 Application Security Foundation training course provides participants with an understanding of the fundamental principles of application security and the requirements of ISO/IEC 27034. The course covers key domains, including the concepts and scope of application security, as well as organizational and application-level planning, application security controls, and monitoring of security controls. Participants will also learn how to verify and align application security practices with organizational objectives and regulatory requirements, including how to tailor an Application Normative Framework (ANF) to define the necessary security controls and processes that help each application meet its Targeted Level of Trust (TLT).

Why You Should Attend

The ISO/IEC 27034 Foundation training course enables participants to understand the fundamental concepts and principles of application security, as well as the structure, components, and requirements of ISO/IEC 27034. This course is designed to prepare professionals to support the implementation and maintenance of application security throughout the software life cycle. By attending this course, participants will learn how ISO/IEC 27034 aligns with other standards, understand key security principles such as confidentiality, integrity, and availability, and gain insight into the roles involved in managing the Organization Normative Framework (ONF) and Application Normative Framework (ANF).

Who Should Attend?

This training course is intended for individuals involved in application security or IT governance; professionals seeking to gain knowledge about ISO/IEC 27034 and its application; individuals involved in the implementation, management, or improvement of application security; and IT professionals, developers, or managers responsible for safeguarding applications.

Learning Objectives

By the end of this training course, participants will be able to describe the structure, scope, and components of the ISO/IEC 27034 series and understand how it aligns with and complements other standards and frameworks; identify and explain key concepts and principles such as confidentiality, integrity, availability, threats, vulnerabilities, and risks, and understand their relevance in securing applications throughout their life cycle; explain the roles and responsibilities in establishing and maintaining the Organization Normative Framework (ONF) and Application Normative Framework (ANF); and describe the processes for validating application security requirements, assessing security risks, verifying security controls, and using KPIs to support continual improvement of application security practices.

Educational Approach

This training course includes essay-type exercises and multiple-choice quizzes, helping participants understand application security concepts and processes. Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions during the training. The quiz structure within the course closely mirrors that of the certification exam, ensuring participants are well-prepared. PECB offers various training course delivery formats, from traditional classroom settings to modern, technology-driven solutions. To learn more about these formats, please click here.

Prerequisites

There are no prerequisites to participate in this training course.

Related courses

Frequently asked questions

How long is the ISO/IEC 27034 Application Security Foundation course?

The course covers two days of content and carries 14 CPD credits. In the self-study format you cover the same material at your own pace.

Is the exam included in the price?

Yes. The course fee includes the PECB certification and examination fees. If you do not pass, one complimentary retake is available within 12 months of your first attempt.

What are the prerequisites for ISO/IEC 27034 Application Security Foundation?

There are no prerequisites to participate in this training course.

Which formats and languages is ISO/IEC 27034 Application Security Foundation available in?

It is available as self-study (English) and hybrid learning (English). Choose the format and language before adding the course to your cart.

What is hybrid learning?

Hybrid learning combines the self-paced course with one day of one-to-one live coaching with the instructor. The day can be split into a half day before you start studying and a half day before your exam, so you go in prepared.

Is there a live class for ISO/IEC 27034 Application Security Foundation?

There is no scheduled live class for this course at the moment. The hybrid option adds one day of one-to-one live coaching with the instructor. Organizations that want a dedicated live session can contact us at [email protected].

Who issues the certificate?

PECB issues the certificate. After passing the exam you can apply for the “PECB ISO/IEC 27034 Foundation” credential. Horus Academy is a PECB Authorized Silver Partner and does not issue the certificate itself.

The “PECB ISO/IEC 27034 Foundation” exam fully meets all the PECB Examination and Certification Program (ECP) requirements. It covers the following competency domains:

Domain 1: Fundamental principles and concepts of application security

Domain 2: Organizational and application security planning, implementation, and monitoring

After passing the exam, you can apply for the credential shown in the table below. The certificate requirements for PECB ISO/IEC 27034 Foundation are:

Designation Exam Professional experience MS audit/assessment experience ASMS project experience Other requirements
PECB Certificate Holder in ISO/IEC 27034 Foundation Pass the PECB ISO/IEC 27034 Foundation Exam None None None Signing the PECB Code of Ethics
  • Certificate and examination fees are included in the price of the training course.
  • Participants will receive more than 200 pages of comprehensive training materials, including practical examples, exercises, and quizzes.
  • Participants who have attended the training course will receive an attestation of course completion worth 14 CPD (Continuing Professional Development) credits.
  • Candidates who have completed the training course with one of our partners and failed the first exam attempt are eligible to retake the exam for free within a 12-month period from the date the coupon code is received because the fee paid for the training course includes a first exam attempt and one retake. Otherwise, retake fees apply.
Price range: CA$299.00 through CA$799.00
Clear
-
+

Course agenda

Day 1: Introduction to application security and ISO/IEC 27034

Day 2: Implementation and verification of application security controls