
Software and Application Security
Program Details
- Language: English
- Fees: €900
- Study Mode: Full-time / Part-time
- Registration Deadline: Q4: September 30th, 2026
- Entry requirements:
- High school diploma or equivalent
- Basic computer literacy
- English Level B1 (CEFR) or equivalent
Study Access
About This Course
This is not your typical lecture-based course. Over the next 12 weeks, you'll get your hands dirty by digging into real code to uncover security flaws.
We will start with two weeks of prep to get you up to speed, then spend eight weeks learning practical security skills - from secure coding and the OWASP Top 10 all the way to AI/LLM security - and finish with a post-course period for the final exam and reflection.
The centerpiece of this course is a hands-on project where you'll analyze a live open-source application, hunt for vulnerabilities, and report your findings just like a professional security consultant.
Learning Objectives
By the end of this course, you will be able to:
- Perform Comprehensive Security Testing: You will gain proficiency in various security testing methodologies, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), and systematic manual penetration testing.
- Apply Secure Design and Coding Practices: You will learn to identify and prevent common vulnerabilities, such as those in the OWASP Top 10, by applying secure coding techniques (input validation, output encoding, memory safety), secure design principles, understanding threat modeling with STRIDE, and following secure development lifecycle (S-SDLC) practices.
- Develop and Analyze Security Requirements: You will learn how to write effective security and privacy requirements, understand compliance with standards like GDPR and HIPAA, and utilize techniques like abuse cases and attack trees to proactively design for security.
- Conduct Security Risk Management: You will be able to assess the security risk of a system using both formal frameworks like NIST and informal, collaborative methods like "Protection Poker" to prioritize and manage security threats effectively.
- Understand AI/LLM Security: You will explore the emerging threat landscape of AI and Large Language Models, including adversarial machine learning, prompt injection attacks, data poisoning, and practical guardrails for securing LLM-integrated applications.
Course Structure
- Prep Weeks (2 Weeks): Before we dive in, it's important to have a solid foundation. You should refresh your knowledge with the "Internet Basics" and "Web Basics" prep courses. To get a head start on the practical side, you'll watch curated videos covering essential tools like Docker for containerization, the command line, SQL for databases, and how APIs work.
- Course Weeks (8 Weeks): This is the core of the course where we'll do a deep dive into practical security topics. Each week will introduce a new area - from the OWASP Top 10 to threat modeling and privacy engineering. You'll reinforce your learning through hands-on activities and weekly assignments that contribute to your final grade.
- Post-Course Weeks (2 Weeks): This period is dedicated to wrapping everything up. You will take the final exam, which covers all the material from the course. This is also a good time to reflect on your learning and consolidate the skills you have gained.
Study Programs
This course is mandatory for the following study programs:
- M.Sc. Cybersecurity
This course is offered in odd quarters and can, therefore1, be selected as an elective in the following study programs:
- M.Sc. Applied AI
- M.Sc. Advanced Digital Reality
- M.Sc. Digital Leadership
- MBA Digital Technologies
- MBA Digital Transformation
1: Generally all mandatory modules of a study program can be selected as an elective in all study programs in which they are not offered as a mandatory module. However, there are several rules that apply. First, at least half of the selected electives have to be taken from your study program. Second, all electives are only available in either odd or even quarters. Therefore, not all electives are available in all programs (given that you want to finish the program within the regular time frame and do not want to take that elective in parallel to your impact project).
Micro Degree
- This course is offered as a micro degree.
- German UDS Micro Degrees are compatible with the European MOOC Consortiums Common Micro Credentials Framework.
- Micro Degrees will be rewarded with an equivalent of 5 ECTS.
- Micro Degrees are offered to non-regular students and require a fee of €900.
Requirements
Knowledge and skills as provided in the Prep courses.
General Information
- Teaching Format: Hands-on Security Analysis
- Total Workload Master: 125h (40h/85h) / 5 ECTS
- Total Workload MBA: 100h (40h/60h) / 4 ECTS
- Total Workload Micro Degree: 125h (40h/85h) / Equivalent to 5 ECTS
- Module coordinator: Tim Garbe
- Examinations: Weekly Assignments, Final Project (including vulnerability reports and presentations), and a Final Exam.
- Offered: Even quarters





.png&w=1080&q=75)
































