← कोर्सच्या मुख्य पानाकडे परत

🗓️ The study plan — 16 lessons, 6 weeks

~3 sessions a week: read the lesson (~15 min) + run and change its section of sec/demo.py (~25 min). Tick lessons off — progress is saved in this browser.

🐢 स्थिर: आठवड्याला 3 सत्रे → 6 आठवड्यांत पूर्ण.
🐇 Fast track: one weekend per two parts → done in 3 weekends.
💰 Cost: zero. Python 3 on your laptop; nothing to install.
0 / 16

WEEK 1 🖍️ The forms desk

Injection, XSS and CSP, cookies/CSRF/CORS/SSRF. Lab: try the crafted input on both queries; change the CSP; add a URL to the SSRF guard.

🏁 Checkpoint: you can explain each web weakness and show the one-line fix.

WEEK 2 🔑 The ID desk

Authentication, OAuth/OIDC, authorization. Lab: verify passwords; break each token check; try Katrina's record as Dipika.

🏁 Checkpoint: you can check a token properly and add the object-level check to any API.

WEEK 3 🗝️ The building desk

Secrets and KMS, IAM and networks, encryption. Lab: scan your own files; shrink a policy; check a TLS config.

🏁 Checkpoint: no secret in code, no unused permission, no old TLS.

WEEK 4 ☸️ The campus gates

Kubernetes RBAC, secrets and network policies, admission. Lab: add a binding; write a default-deny; fix the rejected pod.

🏁 Checkpoint: your cluster denies by default and admits only restricted pods.

WEEK 5 📦 The delivery desk

Dependencies, signing/SBOM/provenance, pipeline threats. Lab: audit a requirements file; tamper with an artifact; walk the leak runbook.

🏁 Checkpoint: every stage from laptop to production has a named guard.

WEEK 6 🤖 The assistant's rulebook

AI and agent security, then the capstone.

🏁 Checkpoint: 🏆 Capstone: threat-model the school parent app end to end — web, identity, cloud, cluster, pipeline and its AI assistant — and prove each control with a test.

🎓 16 / 16 — the security office is yours!

Next: the IAM school goes deep on cloud identity, the System Design school puts security into every box, and the School portal has the rest.