Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC507 Secure Software Development and Code Auditing
This unit explores the principles of secure software development and code auditing. Students will learn to integrate security throughout the software development lifecycle, focusing on secure coding practices, vulnerability detection, and remediation. The unit also covers automated code analysis tools and techniques for auditing codebases to identify potential security flaws. Through practical exercises, students will apply these concepts to real-world software development scenarios, ensuring that security is a priority from the outset.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC404 Foundations of Cybersecurity and ITC405 Introduction to Scripting and Linux Security Tools
UNIT LEARNING OUTCOMES
- Critically evaluate and apply secure coding practices for preventing software vulnerabilities
- Critically evaluate security measures within the secure software development lifecycle
- Conduct vulnerability assessments of software applications and propose strategies to mitigate risks
- Determine and implement automated code analysis tools to identify and address security flaws in codebases
- Propose and communicate strategies for improving the security posture of software applications
CONTENT
- Secure software development
- Common software vulnerabilities: Buffer overflows, SQL injection, XSS
- Secure coding practices: Input validation, error handling, encryption
- The secure software development lifecycle
- Threat modelling and risk assessment in software development
- Code auditing techniques and tools
- Static and dynamic code analysis with automated security testing and CI/CD integration
- Secure software development for web, mobile applications, and API design
- Incident response and patch management for software vulnerabilities
- Ethical considerations in secure software development
ASSESSMENT METHODS
- Vulnerability Analysis Report – 20%
- Secure Coding Practice Evaluation – 30%
- Code Auditing Report – 50%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












