<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35910" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/opentext-fsae" lastchanged="2025-07-29T12:18:45+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Fortify SAST Essentials</title><productcode>FSAE</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-FSAE</fullproductcode><version>22.2</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use Fortify SCA/SSC to correlate, view, and respond to security incidents leveraging Fortify technologies to solve security problems in your applications based on defined topics&lt;/li&gt;&lt;li&gt;Successfully complete the lessons below in an environment that acts as a production environment.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;This course assumes some familiarity working with Fortify SSC and SCA, basic programming skills, the ability to read Java or .Net, have a basic understanding of web technologies: CI/CD DevOps, plus, having computer, browser, and file system navigation skills&lt;/p&gt;</essentials><audience>&lt;p&gt;This course is designed for security champions, administrators who are responsible for deploying and administrating Fortify within their environment; as well as for the Developers and Security Auditors who are taking the first steps toward leveraging the power of Fortify SAST.&lt;/p&gt;</audience><contents>&lt;h5&gt;Module 1:&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Fortify SCA and SSC Introduction&lt;/li&gt;&lt;li&gt;Software Security Center (SSC) Administration&lt;/li&gt;&lt;li&gt;Scan using Fortify Audit Workbench (AWB), Command-Line, and Scan Wizard&lt;/li&gt;&lt;li&gt;Utilize Fortify SCA in IDEs (e.g., Eclipse, IntelliJ, Visual Studio (VS), VS Code)&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2:&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Collaborative audit your scan results in AWB and SSC&lt;/li&gt;&lt;li&gt;Create and analyze your scan results with Filters&lt;/li&gt;&lt;li&gt;Generate reports and create an Audit Guide&lt;/li&gt;&lt;li&gt;Read the Analysis Trace&lt;/li&gt;&lt;li&gt;Recognize noise reduction&lt;/li&gt;&lt;li&gt;Create a Custom Rule&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3:&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Configure and utilize Audit Assistant&lt;/li&gt;&lt;li&gt;Utilize Jira for bug tracking&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Appendix:&lt;/h5&gt;&lt;p&gt;Topics to be covered on your own and in class (as time allows):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AppSec and SAST overviews&lt;/li&gt;&lt;li&gt;Fortify SCA process flow in detail&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:


- Use Fortify SCA/SSC to correlate, view, and respond to security incidents leveraging Fortify technologies to solve security problems in your applications based on defined topics
- Successfully complete the lessons below in an environment that acts as a production environment.</objective_plain><essentials_plain>This course assumes some familiarity working with Fortify SSC and SCA, basic programming skills, the ability to read Java or .Net, have a basic understanding of web technologies: CI/CD DevOps, plus, having computer, browser, and file system navigation skills</essentials_plain><audience_plain>This course is designed for security champions, administrators who are responsible for deploying and administrating Fortify within their environment; as well as for the Developers and Security Auditors who are taking the first steps toward leveraging the power of Fortify SAST.</audience_plain><contents_plain>Module 1:


- Fortify SCA and SSC Introduction
- Software Security Center (SSC) Administration
- Scan using Fortify Audit Workbench (AWB), Command-Line, and Scan Wizard
- Utilize Fortify SCA in IDEs (e.g., Eclipse, IntelliJ, Visual Studio (VS), VS Code)
Module 2:


- Collaborative audit your scan results in AWB and SSC
- Create and analyze your scan results with Filters
- Generate reports and create an Audit Guide
- Read the Analysis Trace
- Recognize noise reduction
- Create a Custom Rule
Module 3:


- Configure and utilize Audit Assistant
- Utilize Jira for bug tracking
Appendix:

Topics to be covered on your own and in class (as time allows):


- AppSec and SAST overviews
- Fortify SCA process flow in detail</contents_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="DE" currency="EUR">2400.00</price></pricelist><miles/></course>