Most Application Security Standards Tell You What "Secure" Looks Like. This One Tells You Whether Your Organization Could Actually Get There From Here.

Most application security standards define the target — the controls, the tiers, the maturity model — and leave the gap between “the standard says this” and “our organization can actually do this” as an exercise for whoever inherits the audit finding. CASS closes that gap directly: it pairs 18 concrete requirements a production application must meet with the organizational preconditions each one depends on, and an honest score of what’s realistically achievable from where you actually stand today, not where the standard assumes you are. In September 2025, a single phished maintainer account triggered the largest npm supply-chain compromise in the ecosystem’s history, spreading through packages downloaded billions of times a week — the kind of failure this course is built to catch before it starts, not explain afterward.
What's Included:
- Lifetime Training Access
- 1-Year Exam License Validity
- Official Online Training
- Official Exam-Prep Quizzes
- Official Course Study Guide
How to Keep Designation Active?
- No CPE Maintenance Needed
- Attend Free Refresher Training
- Contribute 5 Articles Per Year
- Keep Annual Membership Active
- Requires Foundations CGSL + CPSE.
- Foundations Exam Waiver available for 5+ years’ experience — Learn more.
Most Application Security Certifications Teach You a List of Controls to Implement. This Teaches You Whether Your Organization Could Actually Sustain Them.
Most AppSec training treats the checklist as the finish line: implement MFA, add a WAF, generate an SBOM, pass the audit. That’s the floor, not the ceiling — and it’s also where most programs quietly fail, because a control that exists on paper collapses the first time it’s tested by a real incident, an auditor who asks a second question, or the one engineer who understood it leaving the company. CASS is built around the failure mode that list-based training doesn’t address: the gap between what a standard says an application should do and what an organization is actually positioned to deliver.
Built by practitioners who have run this exact framework against real production portfolios — not a framework assembled by a standards committee working from a whiteboard.
You'll score any production application against the same 18-dimension Goalpost Checklist practitioners use in the field — Foundation, Standard, and Advanced tiers — instead of a single pass/fail control-existence check.
You'll apply a working two-axis instrument, the Achievability Score, to weigh Implementation Completeness against Organizational Readiness for any application, so you know what's realistically next instead of just what the standard says should already be true.
You'll make the judgment call most training skips entirely: which of the 18 requirements is a development team's problem to fix, and which is a platform-funding or C-suite problem to escalate — and to whom, specifically.
You'll close the loop the way mature programs actually do: every unmet requirement traced through a Dependency Map to its named organizational owner, so nothing becomes a permanent finding that belongs to no one.
What Sets This Program Apart
Organizational Readiness Comes First, Not Last
Most AppSec programs start with controls and treat organizational context as an excuse for not having them yet. CASS inverts that: every one of the 18 requirements ships with a Dependency Map naming what has to exist organizationally before the requirement is even achievable, and the framework's own guidance is explicit — score Organizational Readiness before Implementation Completeness, because readiness sets the realistic ceiling regardless of team effort.
Real, Dated Incidents Anchor Every Stage
Toyota's five-year-exposed GitHub access key, the 2025 npm Shai-Hulud supply-chain worm, the 2024 Snowflake customer breaches, the xz Utils backdoor, the MOVEit mass-exploitation campaign, and the Change Healthcare ransomware attack — each lesson is anchored to something that actually happened, not a hypothetical control gap.
A Complete Instrument, Not a Sample of One
Most control checklists stop at "implement X." CASS pairs every one of its 345 Foundation- and Standard-tier requirements with a named organizational owner and an escalation path via the Dependency Map and Who Drives, Who Complements model — taught in full, not as illustrative excerpts — plus the two-axis Achievability Score you'll walk out able to run against any real application in your own portfolio.
Vendor-Neutral by Design
The framework never assumes a specific identity provider, CI/CD platform, or container orchestrator — it names the organizational role each has to play (an identity provider, a secrets vault, a CI/CD platform) and leaves the vendor choice to you, so what you learn here applies regardless of your organization's actual stack.
Is This Program Right for You?
CASS builds on the structural literacy and engineering practice CGSL and CPSE establish, then applies both to the specific discipline of application security across an app’s full lifecycle. You can enroll in CASS anytime — your CASS credential requires CGSL and CPSE training complete, and either the Foundations exam passed or an approved Foundations Exam Waiver for qualifying hands-on experience.
You own security posture across a portfolio of production applications and need a working assessment framework, not another compliance checklist.
You run the CI/CD pipeline, secrets vault, or container platform other applications depend on, and you need to know exactly what those applications are entitled to expect from you — and what you’re entitled to expect from them.
You’re accountable for an application’s ownership, classification, and eventual decommissioning, and you want a framework that assigns that accountability explicitly instead of leaving it implicit.
You’re ready — or getting ready — to apply the structural literacy and engineering practice both foundation courses build to the specific discipline of application security.
You may qualify for a Foundations Exam Waiver — you’ll still complete CGSL and CPSE training, but can skip sitting their certification exams.
CASS combined with a Level 3 role specialization credential is one of the paths toward Gloria Institute’s SSMP apex certification.
PROGRAM OUTCOME
What You'll Learn
18 lessons, each building on the last, moving from defining what a production application fundamentally is to decommissioning it without leaving an orphaned trust relationship behind.
Score any application with a working instrument
Apply the 18-dimension Goalpost Checklist — Foundation, Standard, and Advanced tiers — to any production application, including ones this course doesn't name directly, instead of a binary "compliant" label.
Calibrate what's actually achievable
Use the two-axis Achievability Score to weigh Implementation Completeness against Organizational Readiness for a specific application, so you know the realistic next step from where your organization actually stands.
Trace any gap to its organizational owner
For any unmet requirement, use the Dependency Map and Who Drives/Who Complements model to name the correct organizational owner and escalation path — before an incident forces the question.
Decommission an application completely
Execute a full offboarding sequence — every credential revoked, every service account deleted, every integration terminated — instead of leaving an orphaned asset for someone else to discover later.
WHO IS THIS FOR
Built for practitioners who are responsible for how a real application behaves in production, not just how it's designed on paper
CASS assumes the diagnostic vocabulary CGSL builds and the engineering practice CPSE builds. If you’re comfortable with both and want a complete, portfolio-ready assessment framework for application security specifically, this course is calibrated for you.
This course is perfect for
- Application security engineers and product security leads accountable for a portfolio of production applications
- Platform and DevSecOps engineers who own the identity, secrets, or CI/CD infrastructure applications depend on
- Engineering managers and architects accountable for an application's ownership, classification, and lifecycle
- Anyone who has completed CGSL and CPSE and is continuing toward Level 3 or Certified Software Security Master Practitioner (SSMP)
This course may not be for you if
- You're looking for a specific tool's configuration guide rather than an organization-spanning assessment framework
- You want a single-control deep dive — SAST or SCA tuning alone, for instance — rather than the complete 18-dimension picture
- You're not currently working in or near application security, platform engineering, or product engineering
- You're not planning to complete CGSL and CPSE training at some point — this course's content assumes that vocabulary and practice even if your credential is still pending it
- 345 Foundation- and Standard-tier requirements across 18 real production-application dimensions — taught in full, not a curated sample
6 real, dated, sourced incidents anchoring the framework — Toyota, npm’s Shai-Hulud campaign, Snowflake, xz Utils, MOVEit/Cl0p, and Change Healthcare
Two instruments you’ll actually use again: the Dependency Map/Who Drives ownership model and the two-axis Achievability Score, both scoreable against any application in your own portfolio
Built from decades of hands-on practitioner experiences — not a framework assembled by committee
18 lessons, one per dimension of the Perfect App Framework. From what an application fundamentally is to how it ends.
What You Will Study
18 core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.
Certification Exam
Once you’ve completed all 18 lessons, you’re eligible to sit the certification exam. Use the course companion guide, the ready reckoner handout and the comprehensive study guide, which is available for you to prepare.
Group 1 — Foundation and Identity
What a production application fundamentally is: registered, owned, classified, containerized, observable, and a member of the organization's security program. Anchored to Toyota's 2022 disclosure that a subcontractor's public GitHub repository had exposed a live database access key for nearly five years — an application whose ownership and classification were never formally established, so no one was positioned to notice.
How an application begins: a threat model completed before the first sprint, security requirements written into the Business Requirements Document, and an architecture reviewed before code is written. Covers the scoping-stage decisions — including vendor and dependency choices — that quietly set an application's blast radius long before anyone calls it a security issue.
What an application understands about itself: its data, its dependencies, its normal behavior, and how to fail safely. Anchored to the September 2025 npm Shai-Hulud campaign, where organizations only discovered how deep their real dependency graph ran once packages they didn't know they relied on started exfiltrating credentials.
What an application demands from the people and structures around it: named ownership, developer obligations, secrets governance, and practiced emergency readiness. Anchored to Toyota's exposed access key — a textbook case of a requirement that existed as stated policy but was never enforced as practice.
Group 2 — Operation and Discipline
The specific tools and controls a production application actually runs: MFA, RBAC, pipeline security gates, SBOM and AIBOM, endpoint defense, structured logging, and immutable infrastructure. Anchored to the 2024 Snowflake customer breaches, where the absence of one control — mandatory MFA — let years-old, infostealer-harvested credentials walk directly into roughly 165 customer accounts.
The application's default dispositions: every caller unauthenticated, every input potentially malicious, every credential temporary, every finding a defect. Anchored to the Change Healthcare breach, where a single long-lived Citrix credential — unprotected by MFA — was exactly the kind of credential this posture is designed to prevent from existing.
The absolute prohibitions: no secrets outside the vault, no pipeline bypass, no trust based on network location, no undocumented alerts, no compliance theater. Anchored directly to Toyota's T-Connect incident — a hardcoded database access key committed to source control and left in a public repository for five years is the canonical violation of "no secrets outside the vault," and this lesson works backward from that incident to the code-review, pipeline, and secret-scanning gates that would have caught it years earlier.
The non-negotiable affirmative commitments, structurally enforced rather than policy-requested: named ownership, structural MFA, automatic BOM generation, security gates before every merge, complete real-time logging, and tested recovery. Revisits Snowflake and Change Healthcare from the other direction — what "structural MFA" means when it's built into the platform rather than left to individual account configuration.
Group 3 — Dependencies and Ecosystem
The organizational infrastructure, human roles, and shared services an application cannot function securely without: the identity provider, the secrets vault, the CI/CD platform, the AppSec program, the embedded security lead, and the security champion. Anchored to the npm Shai-Hulud campaign, which spread through a compromised publishing token and a maintainer account with no additional identity controls — a direct illustration of what happens when the identity and CI/CD infrastructure an application depends on isn't held to the same standard as the application itself.
What an application contributes back to the security ecosystem: a reachable owner, a current threat model, structured event logs, complete BOMs, specific runbooks, a tested recovery path, and evidenced security posture. Anchored to the same npm compromise from the consumer's side: the multi-day, hundreds-of-packages cascade depended on downstream teams not knowing, in real time, exactly which compromised packages their own build actually pulled in.
What a well-built application makes possible for the teams around it: fast confident development, real-time SOC detection, frictionless audit, immediate incident response, and measurable security program maturity. Frames the Change Healthcare incident's roughly nine-day gap between initial access and ransomware deployment as a detection-and-response failure the application's own logging and alerting posture should have made far harder to sustain.
Group 4 — Capability and Resilience
What an application is actually capable of doing under pressure: patching under emergency conditions, moving between environments, recovering from ransomware, containing a compromise, and demonstrating its security posture on demand. Anchored to the May 2023 MOVEit/Cl0p mass-exploitation campaign, where the gap between "a patch exists" and "over 2,000 affected organizations could actually deploy it before exploitation" defined the incident's scale.
The adversarial and organizational scenarios an application has to withstand: zero-days, ransomware, developer machine compromise, leaked credentials, valid credential misuse, and the departure of its original architect. Anchored to Change Healthcare's ransomware deployment via a single compromised, MFA-less credential — a clear, recent demonstration of "valid credential misuse" as a survival scenario an application has to be built to withstand, not a hypothetical one.
What an application safeguards, in the order that actually matters when trade-offs get made under deadline pressure: the data its users entrust to it, the services that depend on it, the organization that operates it, and the developers who maintain it. Traces the real cost of getting that order wrong through Change Healthcare's roughly $872 million in confirmed damages and months of downstream provider disruption.
Group 5 — Trust, Culture, and Lifecycle
What an application demonstrates through sustained practice: trust through transparency, the right to handle sensitive data, its place in production, and the confidence of integrating teams. Anchored to the trust erosion that followed the Snowflake disclosures — not because Snowflake's own platform was compromised, but because the absence of enforced MFA on customer tenants was, in hindsight, a trust assumption the ecosystem had extended without ever verifying.
What an application's actual security posture reveals about the organization that built it: the security culture, the SDL's quality, the care of the developers, the platform investment, and the C-suite's genuine commitment. Anchored to the xz Utils backdoor (CVE-2024-3094) — a multi-year, patient social-engineering campaign to become a trusted maintainer of a foundational open-source library, which succeeded in part because the broader maintenance culture around it under-resourced the person doing unpaid, unglamorous upkeep work.
How an application sustains and improves its security posture over years, not just at launch: dependency currency, certificate automation, stack lifecycle management, continuous monitoring, and ownership transitions. Anchored to Toyota's access key, technically functional for five straight years precisely because nothing in the application's lifecycle ever forced it to age out.
How an application is decommissioned: every credential revoked, every service account deleted, every integration terminated, every dataset deleted, every orphaned asset eliminated. Closes the framework with decommissioning as a first-class security event — anchored to the same pattern behind Toyota's incident, where an asset outlived its intended purpose and no one's job was to notice.
OBJECTIVES
The Path To Becoming A Practitioner
Every lesson in CASS builds toward a working application security practice — not a list of controls to recite, but the ability to size up a real application, weigh what’s actually achievable, and act. By the end of this course, you’ll be able to run the assessment, not just recognize the checklist.
Score a real application on your own instrument
Apply the 18-dimension Goalpost Checklist to a production application in your own portfolio, and defend the tier — Foundation, Standard, or Advanced — you assign to each requirement.
Calibrate achievability, not just compliance
Use the two-axis Achievability Score to weigh Implementation Completeness against Organizational Readiness, and state what investment would move a specific application to the next level.
Name the owner before the incident does
For any unmet requirement, use the Dependency Map and Who Drives/Who Complements model to identify the correct organizational owner and escalation path — before an audit or incident forces the question.
OVERVIEW
About This Course
CASS is a Level 2 field specialization credential in the Gloria Institute security certification path. Enrollment is open regardless of where you are in Foundations — CGSL and CPSE training is required for the CASS credential to issue, alongside the Foundations exam or an approved Foundations Exam Waiver. Combined with a Level 3 role specialization credential, CASS qualifies the learner for Certified Security Master (CSM), Gloria Institute’s apex certification.
Where CGSL builds the diagnostic vocabulary for structural security failure and CPSE builds the engineering practice to build systems that resist it, CASS applies both to a single discipline: what a production application must be, do, and eventually stop being, across its full lifecycle. This course does not treat organizational context as an excuse for unmet requirements — it treats it as the thing to diagnose first. Every one of the 18 requirements ships with the organizational precondition it depends on, so the question is never just “is this control in place” but “what would have to be true for this control to be sustainable here.”
Every lesson is anchored to a real, dated, sourced incident — from Toyota’s five-year-exposed access key to the 2025 npm supply-chain compromise that spread through billions of weekly downloads. Where this course’s framework maps onto broader security posture — identity, secrets, supply chain, resilience — it does so through the same working instrument throughout, the two-axis Achievability Score, so what you learn here stays usable long after the course ends.
Everything you need to learn application security assessment, apply it, and prepare for certification.
Everything you need to learn the about the application core security aspects, apply it, and prepare for certification.
What's Included
When you enroll, you’ll gain access to the complete interactive course along with the accompanying reference guide. Once you’re prepared, the certification package — which includes the exam voucher and course study guide — will be provided to you as well.
- 18 interactive online lessons covering all 345 Foundation- and Standard-tier requirements across the Perfect App Framework
- The complete Dependency Map and Who Drives, Who Complements ownership model for every dimension — not excerpts
- Branching scenarios and graded knowledge checks in every lesson
- Free companion guide, included with enrollment
- 6 real, dated, sourced incident case studies anchoring the framework
- Official course study guide for certification exam preparation
- Certification exam eligibility and voucher
- Access to the Gloria Institute learner community and future certification path updates
Eligibility & Requirements
CASS is a Level 2 field specialization credential, positioned directly after the two-course Security Foundation Level.
This course builds directly on the structural literacy and engineering practice established by both foundation courses — enrollment in CASS is open regardless of where you are in Foundations, but this content assumes it.
Practitioners with 5+ years of qualifying hands-on application security or secure development experience may apply to waive the CGSL/CPSE certification exam — Foundations training is still required either way. [See Waiver Eligibility →]
Not required, but the course moves at a pace calibrated for someone already working in or near application development, platform engineering, or product security.
Approximately 28–32 hours of core lesson content — covering all 345 Foundation- and Standard-tier requirements in full, not a sample — plus additional time for exam preparation.
CASS, combined with a Level 3 role specialization credential, qualifies the learner for Certified Software Security Master Practitioner (SSMP).
The Credential That Opens Doors
When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.
Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:
- Program-specific competencies achieved
- Digital badge for certifications
- Completion date
- Unique verification number
- Support for certificate verification
Sample Certificate
Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs
No. You can enroll in CASS anytime. To receive your CASS credential, CGSL and CPSE training must be complete, and you'll need to have passed the Foundations exam or been approved for a Foundations Exam Waiver based on qualifying experience.
Yes. Course enrollment includes the 18 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.
Course access details and time limits are set at enrollment — check your specific enrollment terms for exact access duration.
The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.
The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.
Not on its own. CASS is one Level 2 field specialization credential. Combined with a completed Level 3 role specialization credential, it qualifies you for Certified Software Security Master Practitioner (SSMP), Gloria Institute's apex certification.
Practitioners with 5+ years of hands-on application security or secure development experience can apply to waive the CGSL and CPSE certification exam specifically. You'll still complete CGSL and CPSE training in full — the waiver only removes the exam-sitting requirement, since the content itself is what CASS and every Gloria Institute specialization assumes you know. [Apply for a Waiver →]
CASS was built by Gloria Institute practitioners with decades of combined hands-on security engineering, implementation, and consulting experience — not a certification board working from secondhand case studies. Every concept, practice, and framework in this course was developed and refined through real security work: what worked, what didn't, and what changed after watching the same structural failures recur across other practitioners and organizations.
Most Standards Tell You What "Secure" Looks Like. Now Find Out Whether You Could Actually Get There.
Enroll in CASS and score a real application against the 18-dimension framework — with an honest read on what’s achievable from where you actually stand, not just where the standard assumes you are.
CASS builds on Foundations. Add CGSL + CPSE now, or apply for a Foundations Exam Waiver if you’ve got the hands-on experience to skip the exam.
