CASS Certifies That You Know the Framework. This Is What It Takes to Actually Run It — On a Real Application, With No Answer Key.

A certification can teach you a framework and test whether you can apply it to a described scenario. It cannot teach you what happens when you bring that framework into a room with a VP who controls the budget, an engineering team that’s shipped the same way for eight years, or an application whose owner left the company eighteen months ago. DASP is built for that gap: it includes the complete 18-dimension Perfect App Framework at full depth — including the Advanced-tier ceiling that CASS’s certification-level scope doesn’t reach — plus the organizational dynamics (funding, culture, C-suite alignment, change management) that determine whether a framework anyone can learn actually gets implemented anywhere. If you’ve completed CASS, DASP doesn’t repeat it — you move straight into Advanced-tier content and the live practicum. If you haven’t, DASP doesn’t require it first, though it still requires the same CGSL and CPSE foundation every Gloria Institute specialization does. In February 2024, a single compromised credential with no MFA took down the system processing roughly a third of U.S. healthcare transactions — not because no framework existed to prevent it, but because implementing one, organization-wide, is a different problem than knowing what it says.
$3,499
What's Included:
- CASS Certification — full exam & credential, included
- Everything in CASS (345 Foundation- and Standard-tier requirements, full Dependency Map and Who Drives model, certification exam, exam voucher, and retake)
- Full Advanced-tier content across all 18 dimensions (49 additional requirements)
- The complete 8-chapter Organizational Practice track (no Certification equivalent)
- Capstone project: run the full framework against a real application or organization, reviewed by a Gloria Institute practitioner
- Lifetime training access; 12-month structured access window for capstone submission
- Official course study guide and companion guide (Certification + Diploma content)
Already Completed CASS?
- Enroll at $999 off
- Skip directly to Advanced-tier content and the practicum. [Check accelerated-entry eligibility]
- Requires Foundations CGSL + CPSE.
- Foundations Exam Waiver available for 5+ years’ experience — Learn more.
CASS Teaches You to Score an Application Against the Framework. DASP Is What Happens When You Have to Make the Framework True — On an App Nobody Gave You a Head Start On.
Every one of CASS’s 345 requirements comes with a clean, worked incident to anchor it. Real applications don’t come with that clarity — they come with an owner who’s half-convinced the finding isn’t actually their problem, a Dependency Map precondition that would require a platform team’s Q3 roadmap to change, and an Achievability Score that comes back lower than anyone wanted to admit out loud. DASP is built around that difference: the certification-level framework, applied for real, plus the organizational skill the framework alone doesn’t teach.
- You'll score a real application you have access to — not a course example — across the complete Goalpost Checklist, Foundation through Advanced, and defend every tier assignment as your capstone deliverable.
- You'll apply the C-suite Alignment model to name, specifically, which of your organization's leadership dynamics is the actual blocker on a given requirement — not "leadership doesn't prioritize security," but which specific dynamic, and what changes it.
- You'll distinguish accountability, responsibility, and ownership using the framework's own model, so "security is everyone's job" stops being a slogan and starts being a structure you can actually assign.
- You'll build a funding case for a specific gap your Achievability Score identifies, using the same cost-of-breach quantification the framework's own Business Requirements Document guidance describes — a document you could put in front of a real budget conversation.
Built by practitioners who have run this exact framework against real production portfolios, including the organizational conversations a certification exam can’t test.
What Sets This Program Apart
A Live Practicum, Not a Longer Course Example
The single structural thing a 6–9 month format allows that a certification can’t: you run the complete framework against an application or organization you actually have access to, and submit the result as a reviewed capstone — not a graded multiple-choice check on a described scenario.
The Same Six Incidents, Scored to the Ceiling
Toyota, npm’s Shai-Hulud campaign, Snowflake, xz Utils, MOVEit/Cl0p, and Change Healthcare anchor CASS’s Foundation and Standard tiers. DASP revisits each one and scores it against the full Advanced tier too — what would it have actually taken for each of these organizations to be operating at the ceiling, not just above the floor?
The Organizational Practice Track — Content With No Certification Equivalent
Eight dimensions of the framework’s Part 2 — the C-suite alignment problem, the funding model, the culture question, the people dimension, organizational change, and measuring readiness at the portfolio level — none of which appear anywhere in CASS, because they’re not individually-testable technical requirements. They’re the reason frameworks succeed in some organizations and stay laminated on a wall in others.
A Portfolio Deliverable, Not Just a Credential
Your capstone — a complete, real-application assessment across all 18 dimensions plus a funding/readiness case built from it — is something you can put in front of an employer or a client directly, not just a certificate number.
Is This Program Right for You?
DASP includes everything CASS teaches, in full, plus the Advanced tier and the organizational practice content CASS’s certification-level scope doesn’t reach. If you’ve already completed CASS, you can skip directly into Advanced-tier content and the practicum — your CASS work counts. If you haven’t, DASP doesn’t require it first, but still requires the same CGSL and CPSE foundation every Gloria Institute specialization does.
You’re not just scoring applications — you’re responsible for whether the organization around them actually changes, and you need the C-suite and funding vocabulary CASS doesn’t cover.
You need to move a real portfolio from wherever it is now toward the framework’s ceiling, and you need the organizational-change model, not just the technical checklist.
You need a portfolio-ready deliverable — a real, complete framework assessment — that demonstrates capability to a client more directly than a credential alone.
Your Foundation- and Standard-tier work counts. You move straight into the Advanced tier and the practicum.
You’re building a case for promotion, a portfolio for a job search, or proof of capability for a client — and want a Gloria Institute practitioner’s review attached to real work, not just an exam pass.
The DASP program is structured to meet a specific component of the SSMP pathway prerequisites. As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 specialization certifications and one Level 3 specialization certification.
You may not need to sit the Foundations exam — see the Foundations Exam Waiver.
PROGRAM OUTCOME
What You'll Learn
18 Depth lessons, 8 Organizational Practice lessons, and one capstone — moving from scoring an application against the complete framework to leading the organizational change that makes the framework true anywhere in your portfolio.
Score any application to the ceiling, not just the floor
Apply the complete Goalpost Checklist — all 394 requirements, Foundation through Advanced — to a real application, defending every tier assignment against its actual evidence.
Run the full ownership and readiness model live
Use the complete Dependency Map, Who Drives model, and Achievability Score against an application you have real access to, not a course-provided scenario.
Diagnose why a framework isn't landing organizationally
Apply the C-suite Alignment model and the accountability/responsibility/ownership distinction to name the specific organizational dynamic blocking a real requirement — and what changes it.
Build a fundable, portfolio-level readiness case
Aggregate individual Achievability Scores into an Organizational Readiness Score, and build the funding case a real budget conversation would require.
WHO IS THIS FOR
Built for practitioners who are responsible for changing an organization's security posture, not just assessing it
DASP assumes the diagnostic vocabulary CGSL builds, the engineering practice CPSE builds, and (if you’ve completed it) the certification-level framework CASS builds. If you’re the person who has to make a real portfolio’s security posture actually improve — not just document where it currently stands — this program is calibrated for you.
This course is perfect for
- Application security leads and product security heads accountable for a real portfolio's maturity trajectory, not a single assessment
- Platform, DevSecOps, and engineering leaders driving an organization-wide security maturity transition
- Consultants and fractional CISOs who need a portfolio-ready deliverable, not just a credential
- CASS holders continuing toward the full framework depth and a capstone deliverable
This course may not be for you if
- You need a credential in weeks, not months — CASS is the faster path, and DASP includes everything CASS covers, so nothing is lost by starting there first
- You don't have access to a real application or organization to run the capstone against — the practicum is a core, non-optional part of this program
- You're looking for more technical checklist content specifically — CASS's 345 requirements already cover the certification-level technical floor and ceiling of Standard-tier practice; DASP's incremental technical content is the Advanced tier plus organizational material, not a different technical curriculum
- You're not planning to complete CGSL and CPSE training at some point — this program's content assumes that vocabulary and practice even if your credential is still pending it
394 total Goalpost Checklist requirements — the complete Foundation, Standard, and Advanced tiers across all 18 dimensions, with nothing held back
8 organizational-practice chapters with no Certification equivalent — C-suite alignment, funding, culture, people, change, and readiness measurement
1 capstone project, reviewed by a Gloria Institute practitioner — a real-application assessment you can show an employer or client directly
Built from decades of hands-on practitioner experience — not a framework assembled by committee
What You Will Study
18 Depth lessons + 8 Organizational Practice lessons + 1 capstone. From the certification floor to leading the change yourself.
Certification Exam
Once you’ve completed all 18 lessons, you’re eligible to sit the CASS certification exam. Use the course companion guide, the ready reckoner handout and the comprehensive study guide, which is available for you to prepare.
Track 1 — The Complete Framework (Depth)
All 18 dimensions of the Perfect App Framework, at full depth. If you’ve completed CASS, this track’s Foundation- and Standard-tier content is review — jump directly to each lesson’s Advanced-tier extension.
Group 1 — Foundation and Identity
What a production application fundamentally is: registered, owned, classified, containerized, observable, and a member of the organization's security program. Anchored to Toyota's 2022 disclosure that a subcontractor's public GitHub repository had exposed a live database access key for nearly five years — an application whose ownership and classification were never formally established, so no one was positioned to notice.
How an application begins: a threat model completed before the first sprint, security requirements written into the Business Requirements Document, and an architecture reviewed before code is written. Covers the scoping-stage decisions — including vendor and dependency choices — that quietly set an application's blast radius long before anyone calls it a security issue.
What an application understands about itself: its data, its dependencies, its normal behavior, and how to fail safely. Anchored to the September 2025 npm Shai-Hulud campaign, where organizations only discovered how deep their real dependency graph ran once packages they didn't know they relied on started exfiltrating credentials.
What an application demands from the people and structures around it: named ownership, developer obligations, secrets governance, and practiced emergency readiness. Anchored to Toyota's exposed access key — a textbook case of a requirement that existed as stated policy but was never enforced as practice.
Group 2 — Operation and Discipline
The specific tools and controls a production application actually runs: MFA, RBAC, pipeline security gates, SBOM and AIBOM, endpoint defense, structured logging, and immutable infrastructure. Anchored to the 2024 Snowflake customer breaches, where the absence of one control — mandatory MFA — let years-old, infostealer-harvested credentials walk directly into roughly 165 customer accounts.
The application's default dispositions: every caller unauthenticated, every input potentially malicious, every credential temporary, every finding a defect. Anchored to the Change Healthcare breach, where a single long-lived Citrix credential — unprotected by MFA — was exactly the kind of credential this posture is designed to prevent from existing.
The absolute prohibitions: no secrets outside the vault, no pipeline bypass, no trust based on network location, no undocumented alerts, no compliance theater. Anchored directly to Toyota's T-Connect incident — a hardcoded database access key committed to source control and left in a public repository for five years is the canonical violation of "no secrets outside the vault," and this lesson works backward from that incident to the code-review, pipeline, and secret-scanning gates that would have caught it years earlier.
The non-negotiable affirmative commitments, structurally enforced rather than policy-requested: named ownership, structural MFA, automatic BOM generation, security gates before every merge, complete real-time logging, and tested recovery. Revisits Snowflake and Change Healthcare from the other direction — what "structural MFA" means when it's built into the platform rather than left to individual account configuration.
Group 3 — Dependencies and Ecosystem
The organizational infrastructure, human roles, and shared services an application cannot function securely without: the identity provider, the secrets vault, the CI/CD platform, the AppSec program, the embedded security lead, and the security champion. Anchored to the npm Shai-Hulud campaign, which spread through a compromised publishing token and a maintainer account with no additional identity controls — a direct illustration of what happens when the identity and CI/CD infrastructure an application depends on isn't held to the same standard as the application itself.
What an application contributes back to the security ecosystem: a reachable owner, a current threat model, structured event logs, complete BOMs, specific runbooks, a tested recovery path, and evidenced security posture. Anchored to the same npm compromise from the consumer's side: the multi-day, hundreds-of-packages cascade depended on downstream teams not knowing, in real time, exactly which compromised packages their own build actually pulled in.
What a well-built application makes possible for the teams around it: fast confident development, real-time SOC detection, frictionless audit, immediate incident response, and measurable security program maturity. Frames the Change Healthcare incident's roughly nine-day gap between initial access and ransomware deployment as a detection-and-response failure the application's own logging and alerting posture should have made far harder to sustain.
Group 4 — Capability and Resilience
What an application is actually capable of doing under pressure: patching under emergency conditions, moving between environments, recovering from ransomware, containing a compromise, and demonstrating its security posture on demand. Anchored to the May 2023 MOVEit/Cl0p mass-exploitation campaign, where the gap between "a patch exists" and "over 2,000 affected organizations could actually deploy it before exploitation" defined the incident's scale.
The adversarial and organizational scenarios an application has to withstand: zero-days, ransomware, developer machine compromise, leaked credentials, valid credential misuse, and the departure of its original architect. Anchored to Change Healthcare's ransomware deployment via a single compromised, MFA-less credential — a clear, recent demonstration of "valid credential misuse" as a survival scenario an application has to be built to withstand, not a hypothetical one.
What an application safeguards, in the order that actually matters when trade-offs get made under deadline pressure: the data its users entrust to it, the services that depend on it, the organization that operates it, and the developers who maintain it. Traces the real cost of getting that order wrong through Change Healthcare's roughly $872 million in confirmed damages and months of downstream provider disruption.
Group 5 — Trust, Culture, and Lifecycle
What an application demonstrates through sustained practice: trust through transparency, the right to handle sensitive data, its place in production, and the confidence of integrating teams. Anchored to the trust erosion that followed the Snowflake disclosures — not because Snowflake's own platform was compromised, but because the absence of enforced MFA on customer tenants was, in hindsight, a trust assumption the ecosystem had extended without ever verifying.
What an application's actual security posture reveals about the organization that built it: the security culture, the SDL's quality, the care of the developers, the platform investment, and the C-suite's genuine commitment. Anchored to the xz Utils backdoor (CVE-2024-3094) — a multi-year, patient social-engineering campaign to become a trusted maintainer of a foundational open-source library, which succeeded in part because the broader maintenance culture around it under-resourced the person doing unpaid, unglamorous upkeep work.
How an application sustains and improves its security posture over years, not just at launch: dependency currency, certificate automation, stack lifecycle management, continuous monitoring, and ownership transitions. Anchored to Toyota's access key, technically functional for five straight years precisely because nothing in the application's lifecycle ever forced it to age out.
How an application is decommissioned: every credential revoked, every service account deleted, every integration terminated, every dataset deleted, every orphaned asset eliminated. Closes the framework with decommissioning as a first-class security event — anchored to the same pattern behind Toyota's incident, where an asset outlived its intended purpose and no one's job was to notice.
Track 2 — Organizational Practice (Breadth)
5 lessons with no equivalent in CSSS — the organizational dynamics that determine whether a correct cross-tier diagnosis actually produces change anywhere.
A five-rung model for climbing from the Foundation-tier floor to the Advanced-tier ceiling: Known and Owned, Controlled and Defended, Measured and Evidenced, and beyond. Where an organization sits on this ladder determines which investments are realistic next, regardless of what the checklist says should already be true.
The gap between the security posture a framework documents and the posture an organization's leadership dynamics actually produce — named as the most consequential, least-discussed gap in enterprise security. Covers the specific dynamics that create it and how to work with them rather than around them.
Why "security is everyone's responsibility" is true and almost entirely ineffective without a model that distinguishes these three terms — and the specific dysfunctions that follow when an organization doesn't have one.
Why security investment is structurally underfunded relative to the risk it manages — prevented losses are invisible, foregone opportunities are not — and how to build a funding case that survives that asymmetry.
Every control in the framework can be nominally satisfied without producing the security outcome it was designed for, by a culture that treats requirements as constraints to minimize rather than standards to maintain. Covers what makes enforcement durable versus gameable.
Security maturity is a property of individuals, not just organizations, and it changes over a career, an assignment, and exposure to different engineering cultures. Covers what a framework has to account for about the humans implementing it.
The business, technology, threat, and regulatory environments all move independently, and each can make a fixed security investment more or less adequate than it was when it was made. Covers how to navigate a framework implementation through a moving landscape rather than a static one.
Aggregates every individual Achievability Score's Organizational Readiness dimension into a portfolio-level view, answering the question a C-suite actually needs answered: given where the organization is now, what security maturity is realistically achievable over the next 12, 24, and 36 months, and what specific investments get it there.
Capstone Project
Using the complete framework from Track 1 and the organizational model from Track 2, assess a real application or organization you have access to: score it against the full Goalpost Checklist, map its Dependency Map gaps to named owners, calculate its Achievability Score, and build the Organizational Readiness case for closing its largest gap — including a funding argument a real budget conversation would require. Reviewed by a Gloria Institute practitioner against the Institute’s rubric.
OBJECTIVES
The Path To Becoming A Practitioner
Every lesson in DASP builds toward organizational change capability, not just individual assessment skill. By the end of this program, you’ll be able to run the complete framework against a real portfolio and make the case for what it takes to close the gap — not just score the gap.
Score any application to its full ceiling
Apply the complete 394-item Goalpost Checklist to a real application, defending Foundation, Standard, and Advanced tier assignments alike.
Diagnose the organizational blocker, specifically
Use the C-suite Alignment and accountability/ responsibility/ ownership models to name which specific organizational dynamic is blocking a real requirement — not a generic “leadership doesn’t prioritize this.”
Build and defend a portfolio-level readiness case
Aggregate individual application assessments into an Organizational Readiness Score and a funding case that could actually go in front of a budget conversation.
OVERVIEW
About This Course
DASP is a diploma-tier program in the Gloria Institute security certification path, sitting alongside rather than inside the Foundation → Specialization → Master ladder. Enrollment is open regardless of where you are in Foundations or CSSS — CGSL and CPSE training is required for the DASP credential to issue, alongside the Foundations exam or an approved Foundations Exam Waiver, exactly as with every Gloria Institute specialization.
Where CASS teaches the certification-level floor and expected posture of the Perfect App Framework — 345 Foundation- and Standard-tier requirements — DASP teaches the complete framework, ceiling included, and pairs it with the organizational dynamics that determine whether any of it survives contact with a real budget cycle, a skeptical VP, or a culture that treats security requirements as friction to route around. This is not a longer version of CASS’s course examples. It’s the same framework applied to an application or organization the learner actually has access to, reviewed by a practitioner, and submitted as a capstone deliverable.
Every lesson in Track 1 is anchored to the same six real, dated, sourced incidents CASS uses — Toyota, npm’s Shai-Hulud campaign, Snowflake, xz Utils, MOVEit/Cl0p, and Change Healthcare — now scored against the framework’s full Advanced tier. Track 2 has no Certification equivalent: it’s built entirely from the manuscript’s organizational-strategy material, addressing the C-suite alignment problem, funding, culture, the people dimension, organizational change, and portfolio-level readiness measurement.
Everything you need to run the complete application security framework, apply it to real work, and demonstrate that capability directly.
Everything you need to learn the application security pipeline, apply it, and prepare for the CASS certification and this Diploma.
What's Included
When you enroll, you’ll gain access to the complete Depth and Organizational Practice tracks along with the accompanying reference guide. Once you’re prepared, the certification package for the included CASS credential — exam voucher and study guide — will be provided as well, alongside capstone submission and review.
- 18 Depth-track lessons covering the complete Goalpost Checklist (394 requirements, Foundation through Advanced), full Dependency Map, and full Who Drives model for every dimension
- 8 Organizational Practice lessons with no Certification equivalent
- Branching scenarios and graded knowledge checks in every lesson
- Free companion guide and official study guide, covering both the CASS certification exam and DASP capstone preparation
- 6 real, dated, sourced incident case studies, scored to both Standard and Advanced tiers
- The included CASS certification exam voucher and one retake
- Capstone project template, rubric, and one round of practitioner review and feedback
- Access to the Gloria Institute learner community and future certification path updates
Eligibility & Requirements
DASP is a diploma-tier program built on the same Foundation-level requirements as every Gloria Institute specialization.
This program builds directly on the structural literacy and engineering practice established by both foundation courses — enrollment in DASP is open regardless of where you are in Foundations, but this content assumes it.
Practitioners with 5+ years of qualifying hands-on security engineering or governance experience may apply to waive the CGSL/CPSE certification exam — Foundations training is still required either way. [See Waiver Eligibility →]
The practicum is a non-optional core component — you'll need a real system, or realistic access to one, to complete the required assessment.
Note: Sensitive information must be stripped-off before submission. All submissions will be handled in accordance with our privacy policy.
Approximately 55–70 hours of core lesson content across both tracks, plus capstone project time — suggested completion pace of 6–9 months, with a 12-month structured access window.
DASP is designed to satisfy the same pathway requirement toward Certified Software Security Master Practitioner (SSMP). As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 field-specialization certifications and one Level 3 role-specialization certification.
The Credential That Opens Doors
When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.
Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:
- Program-specific competencies achieved
- Digital badge for certifications
- Completion date
- Unique verification number
- Support for certificate verification
Sample Diploma
Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs
CASS certifies the framework's certification-level floor and expected posture — 345 Foundation- and Standard-tier requirements. DASP includes all of that, plus the full Advanced tier, a live practicum against a real application or organization, and eight organizational-practice chapters CASS doesn't cover at all — the C-suite, funding, culture, and change-management content that determines whether the framework actually gets implemented.
Yes. Your Foundation- and Standard-tier work carries over — you move directly into Advanced-tier content, the Organizational Practice track, and the capstone.
No. DASP doesn't require CASS as a prerequisite — it teaches the certification-level content in full as part of Track 1. You do still need CGSL and CPSE training complete (or in progress) and either the Foundations exam passed or an approved Foundations Exam Waiver.
You'll assess a real application or organization you have access to across the complete framework — Goalpost Checklist, Dependency Map, Who Drives model, and Achievability Score — and build a funding/readiness case for closing its largest gap. A Gloria Institute practitioner reviews the submission against the institute's rubric.
Yes — DASP's completion includes the CASS certification exam and credential as part of the program, not as a separate purchase.
DASP is designed to satisfy the same pathway requirement toward Certified Software Security Master Practitioner (SSMP). As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 field-specialization certifications and one Level 3 role-specialization certification.
Suggested completion pace is 6–9 months; your enrollment includes a 12-month structured access window for full track and capstone completion. This involves a rigorous exercise and rushing through the program may not be helpful.
You have the opportunity to submit your capstone project again. For comprehensive information, please refer to the resubmission policy. It's advisable to review this carefully, as it will guide you through the process and requirements involved.
DASP was built by Gloria Institute practitioners with decades of combined hands-on security engineering, implementation, and consulting experience — not a certification board working from secondhand case studies. Every concept, practice, and framework in this course was developed and refined through real security work: what worked, what didn't, and what changed after watching the same structural failures recur across other practitioners and organizations.
CASS Tells You the Framework Is Sound. DASP Is Where You Find Out Whether You Can Actually Make It True.
Enroll in DASP and run the complete Perfect App Framework — floor to ceiling — against a real application, with a practitioner reviewing the result.
Not ready for the full diploma commitment? Start with CASS — everything you learn there carries forward.
