Виталий Пиков · авторские курсыVitaliy Pikov · original courses

Преподавательская картаTeaching map

От материала к проверяемому результатуFrom material to a verifiable outcome

Карта связывает всю сеть авторских материалов с аудиторией, входными знаниями, наблюдаемым результатом, студенческим артефактом и короткой рубрикой. Это не календарное расписание: преподаватель собирает маршрут под роль и исходный уровень группы.The map ties the whole network of materials to an audience, the knowledge assumed on entry, an observable outcome, the artefact a student produces and a short set of assessment criteria. It is not a timetable: the instructor assembles a route around the role and the starting level of the group.

NICE: язык работы, а не название вакансииNICE: a language for the work, not a job title

Work Roles — не должности и не готовые профессии. Здесь они используются как язык ответственности; Task, Knowledge, and Skill statements помогают описать выполняемую задачу и наблюдаемую способность слушателя. Актуальный состав компонентов всегда сверяется на странице NIST.Work Roles are not posts on an org chart and not ready-made professions. Here they serve as a vocabulary for responsibility; the Task, Knowledge, and Skill statements help describe the work being done and a student's observable capability. The current set of components is always checked against the NIST page.

SSDF: различаем final и draftSSDF: tell Final from Draft

NIST SP 800-218, SSDF Version 1.1 — Final и рабочая опора курса. SP 800-218 Rev. 1, Version 1.2 — Draft; перед новым потоком преподаватель проверяет статус на странице публикаций, а проектную политику не строит на черновике без явной оговорки.NIST SP 800-218, SSDF Version 1.1 is Final and is the working basis of the course. SP 800-218 Rev. 1, Version 1.2 is a Draft; before each new intake the instructor checks the status on the publications page, and no project policy is built on a draft without saying so explicitly.

OWASP: риск, требования, тестOWASP: risk, requirements, tests

OWASP Top 10:2025 используется для осведомлённости и приоритизации, ASVS 5.0.0 — для проверяемых требований, WSTG stable или закреплённая versioned release — для сценариев тестирования.OWASP Top 10:2025 is used for awareness and prioritisation, ASVS 5.0.0 for verifiable requirements, and WSTG — the stable branch or a pinned versioned release — for test scenarios.

Инвариант практики. Любая демонстрация атаки выполняется только на локальном или явно разрешённом учебном стенде с зафиксированными границами, лимитами ресурсов и способом остановки. Не направлять сканирование, нагрузку или payload на внешние цели; после работы остановить сервисы и сохранить только необходимые доказательства.Invariant for hands-on work. Any attack demonstration runs only on a local or explicitly authorised teaching lab with fixed boundaries, resource limits and a defined way to stop it. Do not direct scanning, load or payloads at external targets; when the work is done, stop the services and keep only the evidence that is needed.

The courses themselves are taught and published in Russian. This map is in English so you can see the scope of the work and the teaching contract behind each course; write to vitaly@pikov.expert if you need an English-language session or materials.

1. Обучение и проектирование1. Learning and design

Маршрут от постановки учебной или проектной задачи к границам системы и проверяемым требованиям.A route from framing a teaching or project task through to system boundaries and verifiable requirements.

Каталог и выбор маршрутаCatalogue and route selection

Точка входа во всю авторскую сеть.The entry point to the whole network of courses.

АудиторияAudience
Преподаватели, методисты и самостоятельные слушатели.Lecturers, curriculum designers and self-directed learners.
ПредпосылкиPrerequisites
Сформулированная цель обучения и известный исходный уровень группы.A stated learning objective and a known starting level for the group.
Измеримый результатMeasurable outcome
Выбрать последовательность минимум из трёх ресурсов и объяснить переходы между ними.Select a sequence of at least three resources and explain the transitions between them.
АртефактArtefact
Паспорт маршрута с целью, этапами, контрольными точками и итоговой работой.A route plan with the objective, the stages, the checkpoints and the final piece of work.
Критерий / рубрикаAssessment criteria
У каждого этапа указаны результат, доказательство и условие перехода; нет лишних тем вне цели.Every stage states its outcome, its evidence and the condition for moving on; nothing is included that sits outside the objective.
Маршрут и времяRoute and time
20–30 минут на ориентацию, затем переход к профильному направлению.20–30 minutes to get oriented, then on to the relevant specialisation.
Открыть каталогOpen the catalogue

Проектирование информационных системInformation systems design

Системное мышление до выбора технологий.Systems thinking before any choice of technology.

АудиторияAudience
Студенты, аналитики и начинающие архитекторы.Students, analysts and junior architects.
ПредпосылкиPrerequisites
Базовые понятия данных, процессов и программных компонентов.Basic notions of data, processes and software components.
Измеримый результатMeasurable outcome
Построить контекст системы с акторами, потоками данных и границами доверия.Build a system context with actors, data flows and trust boundaries.
АртефактArtefact
Контекстная диаграмма и краткий словарь сущностей и интерфейсов.A context diagram and a short glossary of entities and interfaces.
Критерий / рубрикаAssessment criteria
Граница однозначна, внешние связи подписаны, данные и владельцы не смешаны с реализацией.The boundary is unambiguous, external connections are labelled, and data and owners are not conflated with implementation.
Маршрут и времяRoute and time
4–6 академических часов; затем риск, модель угроз или техническое задание.4–6 academic hours; then risk, the threat model or the requirements specification.
Открыть курсOpen the course

Методика формулирования тем ВКРHow to formulate a graduation thesis topic

От интересной области к проверяемому результату работы.From an area of interest to a verifiable result of the work.

АудиторияAudience
Студенты выпускных курсов и научные руководители.Final-year students and thesis supervisors.
ПредпосылкиPrerequisites
Выбранная предметная область и доступ к объекту исследования или разработки.A chosen subject area and access to the object of research or development.
Измеримый результатMeasurable outcome
Сформулировать тему с объектом, задачей, ожидаемым результатом и способом оценки.State a topic with its object, its task, the expected result and the way it will be assessed.
АртефактArtefact
Одностраничный паспорт темы и перечень проверяемых задач.A one-page topic brief and a list of verifiable tasks.
Критерий / рубрикаAssessment criteria
Тема не равна технологии, результат достижим, а критерий оценки воспроизводим другим экспертом.The topic is not merely a technology, the result is achievable, and the assessment criterion is reproducible by another assessor.
Маршрут и времяRoute and time
2–3 академических часа; затем информационные системы и техническое задание.2–3 academic hours; then information systems and the requirements specification.
Открыть курсOpen the course

Проверяемые требования и РБПОRequirements specifications: verifiable requirements and embedded secure development

Техническое задание как договор о наблюдаемом поведении.The requirements specification as a contract on observable behaviour.

АудиторияAudience
Аналитики, заказчики, архитекторы и специалисты по безопасности.Analysts, customers, architects and security specialists.
ПредпосылкиPrerequisites
Контекст системы, перечень активов и основные сценарии использования.The system context, an asset inventory and the main use cases.
Измеримый результатMeasurable outcome
Преобразовать не менее пяти общих пожеланий в проверяемые security-требования.Turn at least five loosely stated wishes into verifiable security requirements.
АртефактArtefact
Матрица «требование → угроза → проверка → доказательство → владелец».A requirement → threat → check → evidence → owner matrix.
Критерий / рубрикаAssessment criteria
У требования есть условие, субъект, ожидаемое поведение и однозначный критерий приёмки.A requirement has a condition, an actor, the expected behaviour and an unambiguous acceptance criterion.
Маршрут и времяRoute and time
4–6 академических часов; затем SSDF, архитектурный анализ и тестирование.4–6 academic hours; then SSDF, architecture analysis and testing.
Открыть курсOpen the course

2. Управление, риск и доверие2. Governance, risk and assurance

Управленческие решения, риск и доказательства соответствия; международные рамки — основа сравнения, национальные требования — контекст применения.Management decisions, risk and evidence of compliance: international frameworks provide the basis for comparison, national requirements the context in which they are applied.

Система менеджмента информационной безопасностиInformation security and information security management systems

Связь контекста, риска, мер и улучшения.How context, risk, controls and improvement connect.

АудиторияAudience
Руководители ИБ, аудиторы и владельцы процессов.Security managers, auditors and process owners.
ПредпосылкиPrerequisites
Понимание активов, заинтересованных сторон и организационных целей.An understanding of assets, stakeholders and organisational objectives.
Измеримый результатMeasurable outcome
Определить границы СУИБ и проследить один риск до решения, контроля и метрики.Define the boundaries of the ISMS and trace one risk through to a decision, a control and a metric.
АртефактArtefact
Карта контекста СУИБ и карточка обработки риска.An ISMS context map and a risk treatment record.
Критерий / рубрикаAssessment criteria
Границы обоснованы, владелец назначен, остаточный риск и evidence определены.The boundaries are justified, an owner is named, residual risk and evidence are defined.
Маршрут и времяRoute and time
6–8 академических часов; затем углублённая оценка риска и инциденты.6–8 academic hours; then in-depth risk assessment and incident response.
Открыть курсOpen the course

Риски ИБ и реагирование на инцидентыDay I. Security risk, protection of CII, incident response

NIST SP 800-30 Rev. 1 и NIST SP 800-61r3 в прикладном цикле.NIST SP 800-30 Rev. 1 and NIST SP 800-61r3 in one working cycle.

АудиторияAudience
Специалисты ИБ, владельцы рисков и участники CSIRT.Security practitioners, risk owners and CSIRT members.
ПредпосылкиPrerequisites
Перечень активов, бизнес-последствий и доверенных источников данных.An inventory of assets, business impacts and trusted data sources.
Измеримый результатMeasurable outcome
Оценить пять сценариев риска и выбрать обработку с владельцем и сроком проверки.Assess five risk scenarios and choose a treatment for each, with an owner and a review date.
АртефактArtefact
Реестр рисков и короткий playbook одного инцидента.A risk register and a short playbook for one incident.
Критерий / рубрикаAssessment criteria
Сценарий отделён от уязвимости, шкалы определены, решение связано с измеримым контролем.The scenario is kept separate from the vulnerability, the scales are defined, and the decision is tied to a measurable control.
Маршрут и времяRoute and time
6–8 академических часов; затем угрозы КИИ или СУИБ.6–8 academic hours; then threats to critical information infrastructure (CII) or the ISMS.
Открыть курсOpen the course

Угрозы, меры и уязвимости объектов КИИDay II. CII facilities: threats, controls, vulnerabilities

Модель угроз как проверяемая цепочка допущений.The threat model as a testable chain of assumptions.

АудиторияAudience
Аналитики угроз, специалисты КИИ и архитекторы защиты.Threat analysts, critical information infrastructure (CII) specialists and security architects.
ПредпосылкиPrerequisites
Контекст объекта, архитектура и список значимых функций.The facility context, its architecture and a list of its significant functions.
Измеримый результатMeasurable outcome
Проследить минимум три угрозы от источника и условия реализации до меры и проверки.Trace at least three threats from source and preconditions through to a control and its verification.
АртефактArtefact
Фрагмент модели угроз и таблица трассировки мер.A section of the threat model and a control traceability table.
Критерий / рубрикаAssessment criteria
Допущения явны, источник не смешан со способом, мера проверяема и имеет владельца.Assumptions are explicit, the source is not conflated with the method, and each control is verifiable and has an owner.
Маршрут и времяRoute and time
6–8 академических часов; после риска, перед ТЗ и проектированием защиты.6–8 academic hours; after the risk course, before the requirements specification and security design.
Открыть курсOpen the course

Подразделения ТЗИ и их функцииInformation protection units and their functions

Разделение обязанностей и подотчётность.Separation of duties and accountability.

АудиторияAudience
Руководители, специалисты ТЗИ и проектные менеджеры.Department heads, specialists in technical protection of information and project managers.
ПредпосылкиPrerequisites
Оргструктура и перечень процессов обеспечения безопасности.The organisational structure and a list of the security processes it runs.
Измеримый результатMeasurable outcome
Распределить не менее восьми задач ТЗИ без конфликта исполнения и контроля.Allocate at least eight technical protection tasks without leaving execution and control in the same hands.
АртефактArtefact
RACI-матрица и схема эскалации для одного инцидента.A RACI matrix and an escalation path for one incident.
Критерий / рубрикаAssessment criteria
У каждой задачи один accountable, независимость контроля сохранена, эскалация определена.Every task has a single accountable owner, control stays independent, and escalation is defined.
Маршрут и времяRoute and time
3–4 академических часа; затем СУИБ, лицензирование или реагирование.3–4 academic hours; then the ISMS, licensing or incident response.
Открыть курсOpen the course

Лицензирование в сфере ТЗИLicensing for technical protection of information

Сценарий, область действия и доказательства вместо заучивания сроков.Scenario, scope and evidence instead of memorised statutory time limits.

АудиторияAudience
Руководители ТЗИ, юристы и ответственные за соответствие.Heads of technical protection units, lawyers and compliance officers.
ПредпосылкиPrerequisites
Описание работ, исполнителя, заказчика и применимой юрисдикции.A description of the work, the contractor, the customer and the applicable jurisdiction.
Измеримый результатMeasurable outcome
Классифицировать три сценария работ и обосновать необходимость лицензии первичным источником.Classify three work scenarios and justify whether a licence is required, citing the primary source.
АртефактArtefact
Дерево решений и чек-лист доказательств для выбранного сценария.A decision tree and an evidence checklist for the chosen scenario.
Критерий / рубрикаAssessment criteria
Вывод привязан к виду деятельности и актуальной официальной норме; исключения проверены.The conclusion is tied to the type of activity and to the official provision in force; exemptions have been checked.
Маршрут и времяRoute and time
3–4 академических часа; после функций ТЗИ, перед планом соответствия.3–4 academic hours; after the units-and-functions lecture, before the compliance plan.
Открыть курсOpen the course

Сертификация средств защиты информацииCertification of information protection products

Граница объекта оценки и путь доказательств.The boundary of the target of evaluation and the path the evidence takes.

АудиторияAudience
Разработчики СрЗИ, заказчики и специалисты по оценке соответствия.Developers of information protection products, their customers and conformity assessment specialists.
ПредпосылкиPrerequisites
Описание продукта, среды применения и заявленных свойств безопасности.A description of the product, its operating environment and the claimed security properties.
Измеримый результатMeasurable outcome
Сопоставить продуктовый сценарий с подходящим маршрутом оценки и набором исходных данных.Match a product scenario to the appropriate evaluation route and the set of inputs it requires.
АртефактArtefact
Паспорт объекта оценки и схема жизненного цикла доказательств.A target of evaluation datasheet and a diagram of the evidence lifecycle.
Критерий / рубрикаAssessment criteria
Граница продукта стабильна, заявления тестируемы, версии и ответственность за evidence указаны.The product boundary is stable, the claims are testable, and versions and ownership of evidence are stated.
Маршрут и времяRoute and time
4–6 академических часов; затем РБПО, ППК и архитектурный анализ.4–6 academic hours; then secure software development, the FSTEC (Federal Service for Technical and Export Control) software component list and architecture analysis.
Открыть курсOpen the course

3. Платформы и защитная эксплуатация3. Platforms and defensive operations

NICE-направление Implementation and Operation: конфигурация, наблюдаемость, проверка изменения и безопасный откат.The NICE Implementation and Operation category: configuration, observability, verification of a change and safe rollback.

Введение в Astra LinuxIntroduction to Astra Linux SE 1.7

Ориентация в системе через воспроизводимые действия.Finding your way around the system through reproducible actions.

АудиторияAudience
Пользователи и администраторы, начинающие работу с Astra Linux.Users and administrators starting out with Astra Linux.
ПредпосылкиPrerequisites
Базовая командная строка и понятия файла, процесса и учётной записи.Basic command line and the concepts of a file, a process and a user account.
Измеримый результатMeasurable outcome
Найти конфигурацию, проверить права, состояние службы и соответствующую запись журнала.Locate a configuration file, check its permissions, the state of a service and the matching log entry.
АртефактArtefact
Лабораторный протокол из команд, ожидаемого результата и фактических доказательств.A lab log of commands, expected results and the actual evidence.
Критерий / рубрикаAssessment criteria
Каждая команда безопасна, вывод интерпретирован, состояние до и после зафиксировано.Every command is safe, its output is interpreted, and the state before and after is recorded.
Маршрут и времяRoute and time
6–8 академических часов; затем экосистема, модели безопасности и hardening.6–8 academic hours; then the ecosystem, security models and hardening.
Открыть курсOpen the course

Экосистема и уровни защищённости Astra LinuxAstra Linux: the ecosystem and its security levels

Обоснованный выбор варианта платформы и канала сопровождения.A reasoned choice of platform edition and support channel.

АудиторияAudience
Архитекторы, администраторы и специалисты по защите платформ.Architects, administrators and platform security specialists.
ПредпосылкиPrerequisites
Основы Linux и описание требований к учебной или целевой системе.Linux fundamentals and a description of the requirements for the lab or target system.
Измеримый результатMeasurable outcome
Выбрать редакцию, профиль защиты и канал обновлений для заданного сценария.Choose the edition, the security profile and the update channel for a given scenario.
АртефактArtefact
Паспорт frozen-стенда и таблица обоснования выбора.A spec sheet for a frozen lab build and a table justifying the choice.
Критерий / рубрикаAssessment criteria
Версия и источник пакетов зафиксированы, решение трассируется к требованиям, обновление проверяемо.The version and package source are pinned, the decision traces back to requirements, and updating is verifiable.
Маршрут и времяRoute and time
4–6 академических часов; после введения, перед моделями и hardening.4–6 academic hours; after the introduction, before the security models and hardening.
Открыть курсOpen the course

Формальные модели безопасности ОСFormal security models of operating systems

Политика доступа как система правил и проверяемых свойств.Access policy as a system of rules and verifiable properties.

АудиторияAudience
Архитекторы безопасности, администраторы и продвинутые студенты.Security architects, administrators and advanced students.
ПредпосылкиPrerequisites
Права доступа Linux, субъекты, объекты и базовая логика множеств.Linux access permissions, subjects, objects and basic set logic.
Измеримый результатMeasurable outcome
Сравнить дискреционную и мандатную политику и предсказать решение для четырёх запросов.Compare discretionary and mandatory policy and predict the decision for four access requests.
АртефактArtefact
Матрица доступа, набор правил и таблица ожидаемых решений.An access matrix, a rule set and a table of expected decisions.
Критерий / рубрикаAssessment criteria
Правила непротиворечивы, каждый прогноз объяснён моделью, отрицательные случаи включены.The rules are consistent, every prediction is explained by the model, and negative cases are included.
Маршрут и времяRoute and time
4–6 академических часов; затем практическая настройка и тест политики.4–6 academic hours; then hands-on configuration and policy testing.
Открыть курсOpen the course

Hardening Astra Linux и LinuxHardening Astra Linux 1.7 / 1.8 and Linux systems

Безопасное изменение с доказательством и rollback.Safe change with evidence and a rollback.

АудиторияAudience
Linux-администраторы, DevSecOps и специалисты ИБ.Linux administrators, DevSecOps and information security specialists.
ПредпосылкиPrerequisites
Командная строка, systemd, файловые права и резервная копия учебного стенда.The command line, systemd, file permissions and a backup of the lab.
Измеримый результатMeasurable outcome
Применить три настройки hardening и подтвердить отсутствие потери требуемой функции.Apply three hardening settings and confirm that no required function was lost.
АртефактArtefact
Чек-лист «baseline → изменение → positive/negative test → rollback».A "baseline → change → positive/negative test → rollback" checklist.
Критерий / рубрикаAssessment criteria
Изменения минимальны, команды идемпотентны, проверка и откат воспроизводимы.Changes are minimal, the commands are idempotent, and both the check and the rollback are reproducible.
Маршрут и времяRoute and time
1–2 учебных дня на изолированном стенде; затем мониторинг и сканирование.1–2 teaching days in an isolated lab; then monitoring and scanning.
Открыть курсOpen the course

Безопасность WindowsWindows operating system security

Современный baseline без устаревших универсальных рецептов.A current baseline, without outdated one-size-fits-all recipes.

АудиторияAudience
Windows-администраторы, инженеры endpoint security и аудиторы.Windows administrators, endpoint security engineers and auditors.
ПредпосылкиPrerequisites
Учётные записи, групповые политики, журналы и тестовая Windows-система.User accounts, group policy, event logs and a test Windows system.
Измеримый результатMeasurable outcome
Проверить пять настроек baseline и безопасно исправить одно отклонение.Check five baseline settings and safely correct one deviation.
АртефактArtefact
Отчёт baseline с evidence, оценкой влияния и планом отката.A baseline report with evidence, an impact assessment and a rollback plan.
Критерий / рубрикаAssessment criteria
Рекомендация привязана к поддерживаемой версии, исключения описаны, результат перепроверен.Each recommendation is tied to a supported version, exceptions are documented, and the result is re-checked.
Маршрут и времяRoute and time
6–8 академических часов; затем SIEM и проверка уязвимостей.6–8 academic hours; then SIEM and vulnerability assessment.
Открыть курсOpen the course

Архитектура ЭВМ и аппаратная безопасностьComputer architecture and hardware security

Доверие ниже уровня операционной системы.Trust below the operating system.

АудиторияAudience
Системные программисты, архитекторы и инженеры платформ.Systems programmers, architects and platform engineers.
ПредпосылкиPrerequisites
Процессор, память, загрузка ОС и базовая архитектура компьютера.The processor, memory, operating system boot and basic computer architecture.
Измеримый результатMeasurable outcome
Разобрать один путь загрузки и отметить не менее четырёх границ доверия и отказов.Walk through one boot path and mark at least four trust boundaries and points of failure.
АртефактArtefact
Диаграмма boot chain и таблица угроз firmware, памяти и периферии.A boot chain diagram and a table of firmware, memory and peripheral threats.
Критерий / рубрикаAssessment criteria
Каждый trust anchor назван, нарушение свойства связано с проверяемой мерой.Every trust anchor is named, and each broken property is linked to a verifiable control.
Маршрут и времяRoute and time
4–6 академических часов; перед OS hardening или архитектурным анализом.4–6 academic hours; before OS hardening or architecture analysis.
Открыть курсOpen the course

KOMRAD Enterprise SIEMKOMRAD Enterprise SIEM 4.5

От телеметрии к объяснимому детектированию.From telemetry to explainable detection.

АудиторияAudience
Аналитики SOC, администраторы SIEM и blue team.SOC analysts, SIEM administrators and blue teams.
ПредпосылкиPrerequisites
Журналы ОС, IP-сети и базовый жизненный цикл инцидента.Operating system logs, IP networking and the basic incident lifecycle.
Измеримый результатMeasurable outcome
Настроить правило для одного сценария и воспроизвести alert на разрешённом стенде.Configure a rule for one scenario and reproduce the alert in an authorised lab.
АртефактArtefact
Паспорт use case: источник, нормализация, условие, alert, triage и evidence.A use case spec sheet: source, normalisation, condition, alert, triage and evidence.
Критерий / рубрикаAssessment criteria
Есть positive и negative event, ложные срабатывания оценены, шаги triage воспроизводимы.There is both a positive and a negative event, false positives are assessed, and the triage steps are reproducible.
Маршрут и времяRoute and time
1 учебный день на локальном стенде; затем реагирование и улучшение правила.1 teaching day in a local lab; then response and tuning of the rule.
Открыть курсOpen the course

Сканер-ВС и компонент «Инспектор»Scaner-VS 7 and the Inspector component

Сканирование как управляемая проверка, а не список alarm.Scanning as a controlled check, not a list of alarms.

АудиторияAudience
Администраторы, аудиторы и специалисты управления уязвимостями.Administrators, auditors and vulnerability management specialists.
ПредпосылкиPrerequisites
IP-сети, инвентаризация активов и явно разрешённый диапазон стенда.IP networking, asset inventory and an explicitly authorised lab address range.
Измеримый результатMeasurable outcome
Спланировать скан, подтвердить один finding и выполнить retest после изменения.Plan a scan, confirm one finding and run a retest after the change.
АртефактArtefact
План сканирования и карточка finding с evidence, риском, исправлением и retest.A scan plan and a finding card with evidence, risk, remediation and retest.
Критерий / рубрикаAssessment criteria
Scope и лимиты заданы, false positive проверен, вывод не превышает собранные доказательства.Scope and limits are set, false positives are checked, and the conclusion does not go beyond the evidence collected.
Маршрут и времяRoute and time
2 учебных дня; после hardening, перед процессом vulnerability management.2 teaching days; after hardening, before the vulnerability management process.
Открыть курсOpen the course

4. Безопасная разработка и цепочка поставки4. Secure development and the supply chain

От governance SSDF и security-by-design до кода, SCA, SAST, тестов и доказательств выпуска.From SSDF governance and security by design through to code, SCA, SAST, testing and release evidence.

Не ищите шаблон: постройте безопасную разработкуStop looking for a template: build secure development

Главная авторская лекция: люди, инструменты и процессы сначала; честные документы — следом.The flagship lecture: people, tools and processes first; honest documents after.

АудиторияAudience
Руководители разработки, архитекторы, DevSecOps, AppSec и команды соответствия.Development managers, architects, DevSecOps, AppSec and compliance teams.
ПредпосылкиPrerequisites
Реальный программный продукт или процесс, который предстоит построить либо изменить.A real software product or process that is about to be built or changed.
Измеримый результатMeasurable outcome
Отделить бумажную имитацию от работающего контура и найти разрывы в триаде и evidence.Distinguish paper compliance from a working loop and find the gaps in the triad and in the evidence.
АртефактArtefact
Карта people → tools → process → gate → evidence → document для одного значимого риска.A people → tools → process → gate → evidence → document map for one significant risk.
Критерий / рубрикаAssessment criteria
У каждого действия есть владелец, средство, правило, проверяемый выход и связь с решением о выпуске.Every action has an owner, a tool, a rule, a verifiable output and a link to the release decision.
Маршрут и времяRoute and time
45–60 минут; входная лекция перед ГОСТ Р 56939, SSDF и прикладными практиками AppSec.45–60 minutes; the entry lecture before GOST R 56939, SSDF and applied AppSec practice.
Открыть главную лекциюOpen the flagship lecture

Подготовка процессов РБПО к сертификацииPreparing for certification of secure development processes (FSTEC orders No. 240 and No. 230)

Процесс существует только там, где остаётся воспроизводимое evidence.A process exists only where it leaves reproducible evidence.

АудиторияAudience
Руководители разработки, AppSec и команды соответствия.Development managers, AppSec and compliance teams.
ПредпосылкиPrerequisites
Карта текущего SDLC, роли, репозитории и pipeline.A map of the current SDLC, the roles, the repositories and the pipeline.
Измеримый результатMeasurable outcome
Сопоставить один процесс РБПО с практикой SSDF и найти три разрыва evidence.Map one secure software development process onto an SSDF practice and find three evidence gaps.
АртефактArtefact
Матрица process → owner → gate → evidence → retention → gap.A process → owner → gate → evidence → retention → gap matrix.
Критерий / рубрикаAssessment criteria
Оценивается выполненная задача, а не наличие документа; выборки и владельцы определены.The assessment looks at the task actually performed, not at the existence of a document; samples and owners are defined.
Маршрут и времяRoute and time
6–8 академических часов; после общего РБПО, перед внутренним аудитом.6–8 academic hours; after the general secure software development course, before the internal audit.
Открыть курсOpen the course

Разработка безопасного программного обеспеченияSecure software development: the fundamentals

Единая нить от требований к эксплуатации.A single thread from requirements to operation.

АудиторияAudience
Разработчики, архитекторы, QA, DevSecOps и product security.Developers, architects, QA, DevSecOps and product security.
ПредпосылкиPrerequisites
Базовый SDLC, Git и понимание дефекта и риска.A basic SDLC, Git and an understanding of defects and risk.
Измеримый результатMeasurable outcome
Разместить пять security-задач по этапам SDLC и назначить проверяемые gates.Place five security tasks across the SDLC stages and assign verifiable gates.
АртефактArtefact
Security overlay процесса с ролями, входами, выходами и критериями.A security overlay of the process with roles, inputs, outputs and criteria.
Критерий / рубрикаAssessment criteria
Каждый gate блокирует конкретный риск, имеет owner, evidence и процедуру исключения.Every gate blocks a specific risk and has an owner, evidence and an exception procedure.
Маршрут и времяRoute and time
6–8 академических часов; затем ТЗ, архитектура, SCA, SAST и тестирование.6–8 academic hours; then requirements specifications, architecture, SCA, SAST and testing.
Открыть курсOpen the course

Композиционный анализ программного обеспеченияSoftware composition analysis (SCA)

Компонент, происхождение, лицензия и уязвимость в одном решении.Component, provenance, licence and vulnerability in a single decision.

АудиторияAudience
Разработчики, DevSecOps, AppSec и license compliance.Developers, DevSecOps, AppSec and licence compliance.
ПредпосылкиPrerequisites
Сборочная система, dependency manifests и базовые понятия SBOM.A build system, dependency manifests and the basics of SBOM.
Измеримый результатMeasurable outcome
Проследить пять компонентов до версии, источника, лицензии и vulnerability status.Trace five components to their version, source, licence and vulnerability status.
АртефактArtefact
SBOM/ППК-фрагмент и решение allow, remediate, replace или reject.An SBOM or FSTEC software component list extract and an allow, remediate, replace or reject decision.
Критерий / рубрикаAssessment criteria
Прямые и транзитивные зависимости видимы, provenance подтверждён, исключение ограничено сроком.Direct and transitive dependencies are visible, provenance is confirmed, and any exception is time-limited.
Маршрут и времяRoute and time
4–6 академических часов; затем SPDX, ППК и supply-chain gate.4–6 academic hours; then SPDX, the FSTEC software component list and the supply-chain gate.
Открыть курсOpen the course

Статический анализ безопасности приложенийStatic application security testing (SAST)

Finding становится полезным после triage, исправления и retest.A finding becomes useful only after triage, a fix and a retest.

АудиторияAudience
Разработчики C/C++, security champions и AppSec-инженеры.C/C++ developers, security champions and AppSec engineers.
ПредпосылкиPrerequisites
Сборка проекта, unit tests и основы CWE.A buildable project, unit tests and the basics of CWE.
Измеримый результатMeasurable outcome
Классифицировать пять срабатываний, исправить одно истинное и доказать retest.Classify five warnings, fix one true positive and demonstrate the retest.
АртефактArtefact
Карточка finding с CWE, потоком данных, patch, negative test и результатом повторного анализа.A finding card with the CWE, the data flow, the patch, a negative test and the result of the repeat analysis.
Критерий / рубрикаAssessment criteria
Причина устранена, warning не просто подавлен; для C/C++ проверены sanitizers, -fstack-protector-strong и _FORTIFY_SOURCE.The cause is removed rather than the warning merely suppressed; for C/C++, sanitizers, -fstack-protector-strong and _FORTIFY_SOURCE are checked.
Маршрут и времяRoute and time
6–8 академических часов; после secure coding, перед CI quality gate.6–8 academic hours; after secure coding, before the CI quality gate.
Открыть курсOpen the course

Нефункциональное тестирование безопасности ПОNon-functional software security testing (process No. 19)

Надёжность, robustness и attack surface через наблюдаемые свойства.Reliability, robustness and attack surface as observable properties.

АудиторияAudience
QA, разработчики системного ПО и инженеры безопасности.QA, systems software developers and security engineers.
ПредпосылкиPrerequisites
Требования, тестовый стенд и умение автоматизировать проверки.Requirements, a test lab and the ability to automate checks.
Измеримый результатMeasurable outcome
Составить и выполнить три negative test для отказоустойчивости или некорректного ввода.Write and run three negative tests for fault tolerance or malformed input.
АртефактArtefact
Тест-план с oracle, лимитами, логами и минимальным воспроизводимым failure.A test plan with the oracle, resource limits, logs and a minimal reproducible failure.
Критерий / рубрикаAssessment criteria
Есть ожидаемое безопасное поведение, ресурсы ограничены, результат повторяется после исправления.Expected safe behaviour is defined, resources are capped, and the result is reproducible after the fix.
Маршрут и времяRoute and time
4–6 академических часов; после требований и до release decision.4–6 academic hours; after requirements and before the release decision.
Открыть курсOpen the course

Архитектурный анализ и ППКArchitecture analysis. Building and submitting the FSTEC software component list (processes 6, 7, 16, 17)

Доверие к компонентам начинается с границ и provenance.Trust in components starts with boundaries and provenance.

АудиторияAudience
Архитекторы, product security, SCA и руководители разработки.Architects, product security, SCA specialists and development managers.
ПредпосылкиPrerequisites
Контекстная диаграмма, сборочная спецификация и владельцы компонентов.A context diagram, the build specification and the component owners.
Измеримый результатMeasurable outcome
Выделить trust boundaries и принять обоснованное решение по пяти компонентам.Identify the trust boundaries and take a reasoned decision on five components.
АртефактArtefact
Архитектурная схема, ППК/SBOM-фрагмент и журнал решений по компонентам.An architecture diagram, an extract of the FSTEC software component list or SBOM, and a component decision log.
Критерий / рубрикаAssessment criteria
Версия, источник и назначение однозначны; риск, лицензия и замена рассмотрены отдельно.Version, source and purpose are unambiguous; risk, licence and replacement are considered separately.
Маршрут и времяRoute and time
6–8 академических часов; после проектирования, совместно с SCA и threat modeling.6–8 academic hours; after design, alongside SCA and threat modeling.
Открыть курсOpen the course

Лицензии SPDX на русскомSPDX licences in Russian, with suitability verdicts

Справочник для точной идентификации, а не автоматический юридический вывод.A reference for precise identification, not an automatic legal conclusion.

АудиторияAudience
Разработчики, SCA и специалисты license compliance.Developers, SCA and licence compliance specialists.
ПредпосылкиPrerequisites
Текст лицензии или декларация компонента и понимание контекста распространения.The licence text or the component declaration, plus an understanding of the distribution context.
Измеримый результатMeasurable outcome
Идентифицировать пять лицензий корректными SPDX expression и отметить неопределённости.Identify five licences with correct SPDX expressions and flag the uncertainties.
АртефактArtefact
Таблица component → evidence → SPDX ID/expression → obligations → reviewer.A component → evidence → SPDX ID/expression → obligations → reviewer table.
Критерий / рубрикаAssessment criteria
WITH и OR/AND применены корректно, источник текста сохранён, совместимость не заявлена без анализа.WITH and OR/AND are applied correctly, the source of the text is retained, and compatibility is not claimed without analysis.
Маршрут и времяRoute and time
2–4 академических часа; вместе с SCA и политикой допуска компонентов.2–4 academic hours; taken together with SCA and the component approval policy.
Открыть справочникOpen the reference

От рабочего кода к выпускаемому продуктуFrom working code to a shippable product

Жизненный цикл, языки, стеки и четыре класса дефектов.The lifecycle, languages, stacks and four classes of defect.

АудиторияAudience
Разработчики, архитекторы и инженеры выпуска.Developers, architects and release engineers.
ПредпосылкиPrerequisites
Один язык программирования, сборка, тесты и базовый pipeline.One programming language, a build, tests and a basic pipeline.
Измеримый результатMeasurable outcome
Проследить один дефект от причины в коде до gate, исправления и evidence выпуска.Trace one defect from its cause in the code through the gate, the fix and the release evidence.
АртефактArtefact
Мини-кейс assurance: исходный дефект, patch, тест, hardening и release checklist.A short assurance case study: the original defect, the patch, the test, hardening and a release checklist.
Критерий / рубрикаAssessment criteria
Причина и последствие разделены, исправление проверено, артефакты можно повторить из репозитория.Cause and consequence are separated, the fix is verified, and the artefacts can be reproduced from the repository.
Маршрут и времяRoute and time
4–6 академических часов; мост от secure coding к SSDLC и DevSecOps.4–6 academic hours; the bridge from secure coding to SSDLC and DevSecOps.
Открыть курсOpen the course

Языки, архитектура и безопасный SQLLanguages, architecture and safe SQL

Дефект инъекции как связка API, данных и теста.The injection defect as the point where API, data and test meet.

АудиторияAudience
Начинающие разработчики и преподаватели программирования.Junior developers and programming teachers.
ПредпосылкиPrerequisites
Функции, строки, SQL и запуск автоматического теста.Functions, strings, SQL and the ability to run an automated test.
Измеримый результатMeasurable outcome
Заменить небезопасную сборку SQL параметризованным запросом и пройти negative tests.Replace unsafe SQL string building with a parameterised query and pass the negative tests.
АртефактArtefact
Код до/после, набор тестов и краткое объяснение trust boundary.Before and after code, a test suite and a short explanation of the trust boundary.
Критерий / рубрикаAssessment criteria
Payload остаётся данными, функциональный тест сохранён, regression test падает на старом варианте.The payload stays data, the functional test still passes, and the regression test fails on the old version.
Маршрут и времяRoute and time
3–4 академических часа; затем AppSec, SAST и расширенный secure coding.3–4 academic hours; then AppSec, SAST and extended secure coding.
Открыть курсOpen the course

Безопасность приложений: курс и практикумApplication security: the two-day programme and its materials

Threat modeling, требования и тестирование веб-приложения.Threat modeling, requirements and testing of a web application.

АудиторияAudience
Разработчики, QA, AppSec и security champions.Developers, QA, AppSec and security champions.
ПредпосылкиPrerequisites
HTTP, Git, базовая разработка веб-приложений и локальный контейнерный стенд.HTTP, Git, basic web development and a local containerised lab.
Измеримый результатMeasurable outcome
Выбрать три ASVS-требования, выполнить versioned WSTG-сценарии и подтвердить исправление.Select three ASVS requirements, run the versioned WSTG scenarios and confirm the fix.
АртефактArtefact
Threat model, verification matrix и finding с patch и retest.A threat model, a verification matrix and a finding with its patch and retest.
Критерий / рубрикаAssessment criteria
Top 10 используется как обзор риска, ASVS как требование, WSTG как тест; scope и evidence явны.Top 10 is used as a risk overview, ASVS as the requirement and WSTG as the test; scope and evidence are explicit.
Маршрут и времяRoute and time
2 учебных дня плюс самостоятельная лабораторная работа на локальном стенде.2 teaching days plus independent work in a local lab.
Открыть курсOpen the course

Каталог угроз для анализа безопасности ПОThreat catalogue for software security analysis

227 исходных записей: 177 в выборке ПО и 50 вне её области. Справочник и обоснования на русском языке.227 source records: 177 in the software selection and 50 outside its scope. Reference content and rationales are in Russian.

АудиторияAudience
Архитекторы, разработчики и специалисты AppSec, составляющие модель угроз ПО.Architects, developers and AppSec specialists preparing a software threat model.
ПредпосылкиPrerequisites
Описание архитектуры, активов, границ доверия и предполагаемого нарушителя.An architecture description, assets, trust boundaries and an assumed attacker.
Измеримый результатMeasurable outcome
Обосновать применимость пяти угроз и исключение двух для выбранного программного объекта.Justify five applicable threats and two exclusions for a selected software asset.
АртефактArtefact
Матрица: УБИ, актив, условие применимости, решение и обоснование; выгрузка выбранных записей.A matrix of threat ID, asset, applicability condition, decision and rationale; an export of selected records.
Критерий / рубрикаAssessment criteria
Исходное описание отделено от авторского отбора; каждое решение связано с архитектурой, а не только с наличием записи в каталоге.Source descriptions remain separate from the author's selection; every decision follows the architecture, not merely catalogue membership.
Маршрут и времяRoute and time
Рекомендуемая самостоятельная работа: 45–60 минут; затем уточнение модели угроз в процессе РБПО по ГОСТ Р 56939-2024.Suggested independent work: 45–60 minutes; then refine the threat model within secure development under GOST R 56939-2024.
Открыть справочникOpen the reference

5. Проверка защищённости5. Security assessment

NICE-направление Protection and Defense: разрешённая проверка, доказуемый finding и управляемое исправление.The NICE Protection and Defense category: authorised testing, a demonstrable finding and controlled remediation.

Технологии атак и оценка защищённостиAttacker techniques and infrastructure security assessment

Полный цикл от Rules of Engagement до retest.The full cycle from Rules of Engagement to retest.

АудиторияAudience
Специалисты ИБ, аудиторы, администраторы и начинающие пентестеры.Security practitioners, auditors, system administrators and entry-level penetration testers.
ПредпосылкиPrerequisites
TCP/IP, Linux CLI и изолированный стенд Kali Linux с учебной целью.TCP/IP, the Linux command line and an isolated Kali Linux lab with a training target.
Измеримый результатMeasurable outcome
Выполнить безопасную разведку стенда, подтвердить один finding и предложить проверяемое исправление.Run safe reconnaissance against the lab, confirm one finding and propose a verifiable fix.
АртефактArtefact
Scope/Rules of Engagement и отчёт finding → evidence → risk → fix → retest.Scope and Rules of Engagement, plus a finding → evidence → risk → fix → retest report.
Критерий / рубрикаAssessment criteria
Все действия входят в разрешённый scope, трафик ограничен, вывод подтверждён и воспроизводим.Every action stays inside the authorised scope, traffic is constrained, and each conclusion is confirmed and reproducible.
Маршрут и времяRoute and time
5 лекций и практикум; демонстрации только на локальной учебной инфраструктуре.5 lectures and a workshop; demonstrations run only on local training infrastructure.
Открыть курсOpen the course

Авторские направления углубленияAdvanced specialisations

SAST, базовый и углублённый пентест, фаззинг — выбор по задаче, а не по инструменту.SAST, basic and advanced penetration testing, fuzzing — chosen by the problem, not by the tool.

АудиторияAudience
Разработчики, DevSecOps, SOC, аудиторы и практикующие специалисты ИБ.Developers, DevSecOps and SOC engineers, auditors and practising security specialists.
ПредпосылкиPrerequisites
Базовый профиль выбранного трека и готовность работать на разрешённом стенде.The baseline profile for the chosen track and a willingness to work in an authorised lab.
Измеримый результатMeasurable outcome
Выбрать один трек и сформулировать итоговую работу с наблюдаемым security-результатом.Pick one track and define a final project with an observable security outcome.
АртефактArtefact
Индивидуальный план: входной тест, модули, лабораторные evidence и итоговая аттестация.An individual plan: entry test, modules, lab evidence and final assessment.
Критерий / рубрикаAssessment criteria
Трек соответствует роли, prerequisite gaps закрыты, итог проверяет объяснение причины и исправления.The track matches the role, prerequisite gaps are closed, and the final assessment requires the learner to explain both root cause and fix.
Маршрут и времяRoute and time
От 3 до 10 учебных дней в зависимости от направления и входной диагностики.3 to 10 teaching days, depending on the track and the entry diagnostic.
Открыть направленияOpen the specialisations

Первичные ориентиры для актуализацииPrimary sources for keeping this current