LectureIn Russian
Why borrowed regulations do not create security: people, tools and processes as the load-bearing triad, evidence as the trace of real work, and documents as an honest projection of the operating system.
Read the lecture ↗
LectureIn Russian
How to write a specification that can actually be built and accepted: GOST 19 and 34 series, atomic requirements and acceptance test programmes.
Full description
How to write a specification that can actually be built and accepted: GOST 19 and 34 series, atomic requirements and acceptance test programmes. Secure development under GOST R 56939-2024 as the load-bearing axis — requirements → architecture → threat model → detection → remediation — with SAST/SCA/SBOM/fuzzing artefacts and an acceptance package.
Read the lecture ↗
CourseIn Russian
A complete methodology for preparing a security-product vendor for certification against GOST R 56939-2024: a road map, 25 process regulations and plans covering processes 5.1–5.25, a hardened C/C++ compiler…
Full description
A complete methodology for preparing a security-product vendor for certification against GOST R 56939-2024: a road map, 25 process regulations and plans covering processes 5.1–5.25, a hardened C/C++ compiler under GOST R 71206-2024, and verification via IDEF0 and AppSec Table Top.
Explore the course ↗
LectureIn Russian
A six-part teaching series: vulnerabilities and secure development, the 25 secure development processes, the requirements of GOST R 56939-2024, process certification under FSTEC Order No. 240, and practical adoption.
Read the lecture ↗
LectureIn Russian
A complete teaching day: the secure software lifecycle and extreme programming, the ten layers of a modern technology stack, one task solved in four languages, and an analysis of four security defects with fixes and tests.
Read the lecture ↗
LectureIn Russian
A teaching day on language classification and how technology choice affects security, on Shift Left, and on architectural trust boundaries.
Full description
A teaching day on language classification and how technology choice affects security, on Shift Left, and on architectural trust boundaries. Lab work: a hardened SQLite schema, CWE-89, parameterised queries, allowlists and the RED → GREEN cycle.
Read the lecture ↗
CourseIn Russian
A two-day educational lab: day 1 with a teaching slide deck, 15 original diagrams, a full transcript, a session protocol and lab materials; a glossary of 60+ terms and an instructor's guide; day 2 with the…
Full description
A two-day educational lab: day 1 with a teaching slide deck, 15 original diagrams, a full transcript, a session protocol and lab materials; a glossary of 60+ terms and an instructor's guide; day 2 with the programme and a prepared archive structure.
Explore the course ↗
Practical workshopIn Russian
A method for local hands-on practice: isolating the Docker target, pinning the version, collecting evidence, classifying challenges, prevention for A01–A06, and report templates.
Full description
A method for local hands-on practice: isolating the Docker target, pinning the version, collecting evidence, classifying challenges, prevention for A01–A06, and report templates. Linked to the open archive of day-one source materials.
Open the workshop ↗
LectureIn Russian
Managing the third-party component supply chain: the draft Russian national standard, SBOM in CycloneDX format, and requirements for vulnerability and licence analysis tooling.
Read the lecture ↗
LectureIn Russian
The principles of static code analysis, vulnerability classes (CWE, OWASP), CI/CD integration, Russian and international tooling, and secure development requirements.
Read the lecture ↗
LectureIn Russian
The requirements of process 5.19 in GOST R 56939-2024, simulating attacker behaviour, 11 classes of checks, 6 practical cases and an original 38-point checklist.
Read the lecture ↗
CourseIn Russian
A full course on secure development practice beyond fuzzing and static analysis: attack surface, 9 analysis techniques, 6 architecture cases, and building the software component list and submitting it to FSTEC of Russia.
Explore the course ↗
LectureIn Russian
A five-lecture teaching day: security drivers and terminology, the ISO/IEC 27000 family, policy and RACI, the secure lifecycle under GOST R 56939-2024, risk management under ISO/IEC 27005, internal audit under…
Full description
A five-lecture teaching day: security drivers and terminology, the ISO/IEC 27000 family, policy and RACI, the secure lifecycle under GOST R 56939-2024, risk management under ISO/IEC 27005, internal audit under ISO 19011, and management review of the ISMS.
Read the lecture ↗
ReferenceIn Russian
227 threats with affected objects and selection rationales: 177 apply to software directly or under stated conditions, while 50 fall outside the defined software analysis scope.
Full description
227 threats with affected objects and selection rationales: 177 apply to software directly or under stated conditions, while 50 fall outside the defined software analysis scope. Two coordinated lists with search, filters and CSV export. Content in Russian.
Open the reference ↗