ข้ามไปยังเนื้อหา
Security by Design
Section 1 : บทนำและพื้นฐาน (5 นาที)
Lesson 1 : What is Security by Design? (10 นาที)
ตัวอย่าง บทเรียน
ยุบ
Lesson 1 : What is Security by Design? (10 นาที)
3 หัวข้อ
นิยามของ Security by Design vs. Security as an Afterthought (เปรียบเทียบการออกแบบตั้งแต่ต้นกับการมาแก้ทีหลัง)
แนวคิด “Shift Left” คืออะไร? (ความสำคัญของการขยับเรื่อง Security ไปทางซ้ายของกระบวนการผลิต)
Cost of Fixing Defects and Key Takeaways
Lesson 2 : Core Security Principles (10 นาที)
ขยาย
Lesson 2 : Core Security Principles (10 นาที)
3 หัวข้อ
CIA Triad (Confidentiality, Integrity, Availability) ในบริบทของการออกแบบ
Defense in Depth (แนวคิดการออกแบบความปลอดภัยหลายชั้น)
Principle of Least Privilege
Section 2 : กระบวนการออกแบบและวิเคราะห์ภัยคุกคาม (35 นาที)
Lesson 1 : Security in SDLC Phases (10 นาที)
ขยาย
Lesson 1 : Security in SDLC Phases (10 นาที)
3 หัวข้อ
ภาพรวมของ Software Development Life Cycle (SDLC)
การแทรก Security Checklist ในจุดต่างๆ ของ Requirement และ Design
Key Takeaways and Quiz
Lesson 2 : Introduction to Threat Modeling (15 นาที)
ขยาย
Lesson 2 : Introduction to Threat Modeling (15 นาที)
3 หัวข้อ
Threat Modeling คืออะไร? (การฝึกคิดแบบ Hacker)
4 คำถามสำคัญในการวิเคราะห์
แนะนำ STRIDE Model (Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege)
Lesson 3 : Attack Surface Reduction (10 นาที)
ขยาย
Lesson 3 : Attack Surface Reduction (10 นาที)
3 หัวข้อ
นิยามของ Attack Surface (พื้นที่โจมตี)
เทคนิคการลดพื้นที่โจมตี (เช่น การปิด Feature ที่ไม่ใช้, ลดจำนวน Input points)
Key Takeaways
Section 3 : สถาปัตยกรรมและการป้องกัน (35 นาที)
Lesson 1 : Zero Trust Architecture (10 นาที)
ขยาย
Lesson 1 : Zero Trust Architecture (10 นาที)
2 หัวข้อ
แนวคิด Death of the Perimeter
หลักการ “Never Trust, Always Verify” (อย่าไว้ใจใครหรือระบบใดโดยอัตโนมัติ)
Lesson 2 : Secure Authentication & Authorization Design (15 นาที)
ขยาย
Lesson 2 : Secure Authentication & Authorization Design (15 นาที)
3 หัวข้อ
|
1 แบบทดสอบ
การออกแบบระบบ Login ที่ปลอดภัย (MFA, Password Policy)
ความแตกต่างระหว่าง Authentication (ระบุตัวตน) vs. Authorization (กำหนดสิทธิ์)
การจัดการ Session และ Token (เช่น JWT, OAuth)
Lesson 7 Quiz
Lesson 3 : Data Protection Strategies (10 นาที)
ขยาย
Lesson 3 : Data Protection Strategies (10 นาที)
3 หัวข้อ
Encryption at Rest (การเข้ารหัสข้อมูลที่จัดเก็บ)
Encryption in Transit (การเข้ารหัสข้อมูลขณะส่ง)
กฏ No Hardcoded Secrets
Section 4 : การตรวจสอบและการส่งมอบ (30 นาที)
Lesson 1 : Security Testing & Validation (10 นาที)
ขยาย
Lesson 1 : Security Testing & Validation (10 นาที)
3 หัวข้อ
ความแตกต่างของ SAST (Static Analysis – ตรวจโค้ด) และ DAST (Dynamic Analysis – ตรวจตอนรัน)
บทบาทและความจำเป็นของ Penetration Testing
Key Takeaways
Lesson 2 : Privacy by Design & PDPA/GDPR (10 นาที)
ขยาย
Lesson 2 : Privacy by Design & PDPA/GDPR (10 นาที)
2 หัวข้อ
ความสัมพันธ์และความต่างระหว่าง Security (ความปลอดภัย) และ Privacy (ความเป็นส่วนตัว)
หลักการ Privacy by Design (เช่น Data Minimization เก็บข้อมูลเท่าที่จำเป็น) และ ข้อควรระวังและการปฏิบัติตามกฎหมาย PDPA ของไทย
Lesson 3 : Summary & Case Study (10 นาที)
ขยาย
Lesson 3 : Summary & Case Study (10 นาที)
4 หัวข้อ
บทเรียนราคาแพงจากอดีต เพื่อการสร้างอนาคตที่ปลอดภัย
สรุป Checklist 5 ข้อสำคัญก่อนเริ่มโปรเจกต์ใหม่
ยกตัวอย่าง Case Study ความล้มเหลวจากการขาด Security by Design (เช่น ข้อมูลหลุดจาก IDOR)
course completion
หัวข้อก่อนหน้า
หัวข้อถัดไป
แนวคิด “Shift Left” คืออะไร? (ความสำคัญของการขยับเรื่อง Security ไปทางซ้ายของกระบวนการผลิต)
Scroll to Top
Search for:
Search Button
เข้าสู่ระบบ
การเข้าถึง คอร์สเรียน นี้จำเป็นต้องเข้าสู่ระบบ โปรดระบุข้อมูลประจำตัวของคุณที่ด้านล่าง!
ชื่อผู้ใช้หรือที่อยู่อีเมล
รหัสผ่าน
บันทึกการใช้งานของฉัน
ลืมรหัสผ่านใช่ไหม?
ลงทะเบียน
ยังไม่มีบัญชีใช่ไหม? ลงทะเบียนเลย!
ลงทะเบียนบัญชีใหม่