Application Security Foundations
The starting sequence for engineers who are new to application security at Strata — what gets measured, against which standards, and where the platform's own reasoning about priority comes from.
- Audience
- Engineers new to application security, or new to how Strata specifically measures and prioritizes it.
- Level
- Introductory
- Depth
- Short — six steps, mostly reference material with one hands-on tool at the end.
Prerequisites
- None — this is the starting point.
Learning Objectives
- Understand how the Knowledge Center is organized and where to go for what.
- Recognize the standards (OWASP, CWE, CVSS, and related frameworks) Strata's own findings map to.
- Be able to reason about priority beyond a raw severity score.
0 of 6 complete (0%)
Progress is saved only in this browser.
Steps
1. Knowledge Center
OpenPage
Start with the map before the territory — this is the front door to everything else in every other path.
2. Framework Coverage
OpenPage
See every standard Strata maps findings to in one place before going deep on any single one.
3. OWASP Coverage
OpenPage
The OWASP Mobile Top 10 is the framework the rest of the mobile-specific content in this library assumes you recognize.
4. Vulnerability Prioritization Beyond CVSS
OpenArticle
A severity score alone doesn't tell you what to fix first — this is the reasoning every prioritization-related path in this library builds on.
5. Vulnerability Prioritization Matrix
OpenDecision Center
Apply the reasoning from the previous step directly, with your own inputs, instead of just reading about it.
6. Secure SDLC Planner
OpenDecision Center
Zoom out from a single finding to the process that should catch findings like it earlier next time.
Related Learning Paths
Engineering Manager AppSec
For managers, directors, and CTOs who need to report on application security risk and prioritize a backlog without necessarily writing the fixes themselves.
Vulnerability Prioritization
A focused sequence on the specific question of what to fix first — the standards involved, why severity alone is an incomplete answer, and a tool to apply the reasoning to a real finding.