Unit rationale, description and aim

Software security is now a core professional requirement across all sectors. Organisations need graduates who can design, build, test and maintain software that is secure by design, resilient in operation, and aligned with contemporary assurance practices. This unit addresses that need by extending students’ software development knowledge into secure software engineering, with emphasis on secure Software Development Life Cycle (SDLC) practices, threat modelling, secure coding, verification, DevSecOps, and the security risks associated with AI-assisted development. Current industry and standards bodies emphasise secure software development practices and secure-by-design principles.

This unit examines the principles and practices of secure software engineering in modern development environments. Students apply secure software lifecycle practices, perform threat modelling, implement secure coding and code review techniques, evaluate software against recognised security requirements, and integrate security into automated delivery pipelines. The unit also considers software supply chain risk, dependency management, static and dynamic analysis, and the secure use of AI-assisted development tools.

The aim of this unit is to develop students’ capacity to design, implement, verify and improve software systems using secure engineering practices that are technically robust, professionally responsible and aligned with current standards.

2027 10

Campus offering

No unit offerings are currently available for this unit.

Prerequisites

ITEC614 Cyber Security Concepts AND ITEC619 Programming Fundamentals

Learning outcomes

To successfully complete this unit you will be able to demonstrate you have achieved the learning outcomes (LO) detailed in the below table.

Each outcome is informed by a number of graduate capabilities (GC) to ensure your work in this, and every unit, is part of a larger goal of graduating from ACU with the attributes of insight, empathy, imagination and impact.

Explore the graduate capabilities.

Analyse software systems and development contexts ...

Learning Outcome 01

Analyse software systems and development contexts using secure software lifecycle principles and threat modelling methods.
Relevant Graduate Capabilities: GC1, GC7

Apply secure coding, review and testing practices ...

Learning Outcome 02

Apply secure coding, review and testing practices to design and implement more secure software solutions.
Relevant Graduate Capabilities: GC2, GC10

Evaluate software security using recognised verifi...

Learning Outcome 03

Evaluate software security using recognised verification approaches, tools and standards, including static, dynamic and dependency analysis.
Relevant Graduate Capabilities: GC2, GC8

Critically evaluate professional and governance is...

Learning Outcome 04

Critically evaluate professional and governance issues in secure software engineering, including software supply chain risk and the security implications of AI-assisted development.
Relevant Graduate Capabilities: GC1, GC12

Content

Topics will include:

Secure software engineering foundations

Secure SDLC, secure-by-design and secure-by-default principles, security requirements, and assurance in software development.

Threat modelling and secure design

Threat modelling approaches, attack surface analysis, trust boundaries, misuse cases, and secure design patterns.

Secure coding and verification

Secure coding practices, OWASP Top 10 and OWASP ASVS, code review, input validation, authentication and authorisation controls, error handling, and secrets management.

Software testing and analysis

Static analysis, dynamic analysis, software composition analysis, fuzzing, dependency and vulnerability management, and remediation workflows.

DevSecOps and software supply chain security

Security in CI/CD pipelines, automation, policy-as-code, container and IaC security, SBOM concepts, package integrity, and open-source component risk.

AI-assisted development and professional practice

Security risks of AI-generated code, governance of AI coding tools, prompt-related risks, hallucinated or insecure code patterns, verification of AI-assisted outputs, and ethical and professional responsibilities.

Assessment strategy and rationale

The assessment strategy is designed to progressively develop students’ capability from analysis to implementation and critical evaluation. Assessment 1 requires students to analyse a software system or scenario using secure SDLC and threat modelling principles, building foundational capability in identifying risks, trust boundaries and security requirements. Assessment 2 then requires students to apply secure coding and verification techniques to implement or improve a software artefact, demonstrating practical skill in secure development, testing and remediation. Assessment 3 requires students to critically evaluate a complex software security scenario involving issues such as software supply chain risk, DevSecOps controls, or AI-assisted development, and justify an appropriate secure engineering response. Together, these assessments provide a coherent progression from analysis to application to advanced evaluation, and support achievement of all learning outcomes. To pass this unit, students must demonstrate competence in all learning outcomes and achieve an aggregate mark of at least 50%.

Overview of assessments

Task 1: Secure design and threat modelling repor...

Task 1: Secure design and threat modelling report

Students analyse a supplied software system, architecture or case scenario and produce a structured threat model and secure design review. They identify assets, trust boundaries, likely threats, security requirements and recommended design controls.

Submission Type: Individual

Assessment Method: Practical task

Artefact: report (1200 words)

Weighting

25%

Learning Outcomes LO1, LO3
Graduate Capabilities GC1, GC2, GC7, GC8

Task 2: Applied secure coding and verification t...

Task 2: Applied secure coding and verification task

Students apply secure coding and verification practices to a supplied or student-developed software artefact. They implement or improve controls, conduct appropriate analysis or testing, document vulnerabilities and remediation, and justify the technical decisions made.


Submission Type: Individual

Assessment Method: Presentation

Artefact: 1500 words report plus code and supporting appendix.+ Online Viva

Weighting

35%

Learning Outcomes LO2, LO3
Graduate Capabilities GC2, GC8, GC10

Task 3: Critical software security case analysis...

Task 3: Critical software security case analysis

Students critically evaluate a complex software security scenario involving issues such as insecure dependencies, CI/CD weaknesses, software supply chain compromise, or risks arising from AI-assisted code generation. They justify a secure engineering response for both technical and organisational stakeholders.

Submission Type: Individual

Assessment Method: Presentation

Artefact: Live / Recorded with face-overlay Presentation (7-8 minutes) + Online Viva

Weighting

40%

Learning Outcomes LO1, LO2, LO3, LO4
Graduate Capabilities GC1, GC2, GC10, GC12

Learning and teaching strategy and rationale

This unit is delivered fully online, primarily in an asynchronous mode, through recorded lectures, guided learning resources, practical lab activities, applied coding exercises, case-based learning and discussion forums. Students engage with realistic software development and assurance scenarios to develop secure design, implementation and evaluation skills. Learning activities are structured to support AQF Level 9 learning by requiring analysis of complex technical problems, justification of design decisions, critical evaluation of tools and standards, and reflective consideration of security, risk and responsibility. To further support student learning, up to three optional synchronous online workshops will be offered during the unit for assessment consultation and clarification.

Students should plan to commit approximately 150 hours to this unit over the semester, including participation in learning activities, independent study, readings and assessment preparation.

Representative texts and references

Representative texts and references

Anderson, R. (2020). Security engineering: A guide to building dependable distributed systems (3rd ed.). Wiley.

Mack, S. D. (2024). The DevSecOps playbook: Deliver continuous security at speed. Wiley.

National Institute of Standards and Technology. (2022). Secure software development framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (Special Publication 800-218). U.S. Department of Commerce.

National Institute of Standards and Technology. (2024). Secure software development practices for generative AI and dual-use foundation models: An SSDF community profile (Special Publication 800-218A). U.S. Department of Commerce.

OWASP Foundation. (n.d.). OWASP application security verification standard (ASVS).

OWASP Foundation. (n.d.). OWASP software assurance maturity model (SAMM).

OWASP Foundation. (2025). OWASP Top 10: Web application security risks.

Pfleeger, C. P., Pfleeger, S. L., & Coles-Kemp, L. (2023). Security in computing (6th ed.). Pearson.

Ransome, J. F., Misra, A., & Merkow, M. S. (2022). Practical core software security: A reference framework. CRC Press.

Sommerville, I. (2023). Engineering software products: An introduction to modern software engineering (Global ed.). Pearson.

Locations
Credit points
Year

Have a question?

We're available 9am–5pm AEST,
Monday to Friday

If you’ve got a question, our AskACU team has you covered. You can search FAQs, email, live chat, call – whatever works for you.

Live chat with us now

Chat to our team for real-time
answers to your questions.

Launch live chat

Visit our FAQs page

Find answers to some commonly
asked questions.

See our FAQs