Unit rationale, description and aim
Software security is now a core professional requirement across all sectors. Organisations need graduates who can design, build, test and maintain software that is secure by design, resilient in operation, and aligned with contemporary assurance practices. This unit addresses that need by extending students’ software development knowledge into secure software engineering, with emphasis on secure Software Development Life Cycle (SDLC) practices, threat modelling, secure coding, verification, DevSecOps, and the security risks associated with AI-assisted development. Current industry and standards bodies emphasise secure software development practices and secure-by-design principles.
This unit examines the principles and practices of secure software engineering in modern development environments. Students apply secure software lifecycle practices, perform threat modelling, implement secure coding and code review techniques, evaluate software against recognised security requirements, and integrate security into automated delivery pipelines. The unit also considers software supply chain risk, dependency management, static and dynamic analysis, and the secure use of AI-assisted development tools.
The aim of this unit is to develop students’ capacity to design, implement, verify and improve software systems using secure engineering practices that are technically robust, professionally responsible and aligned with current standards.
Campus offering
No unit offerings are currently available for this unit.Learning outcomes
To successfully complete this unit you will be able to demonstrate you have achieved the learning outcomes (LO) detailed in the below table.
Each outcome is informed by a number of graduate capabilities (GC) to ensure your work in this, and every unit, is part of a larger goal of graduating from ACU with the attributes of insight, empathy, imagination and impact.
Explore the graduate capabilities.
Analyse software systems and development contexts ...
Learning Outcome 01
Apply secure coding, review and testing practices ...
Learning Outcome 02
Evaluate software security using recognised verifi...
Learning Outcome 03
Critically evaluate professional and governance is...
Learning Outcome 04
Content
Topics will include:
Secure software engineering foundations
Secure SDLC, secure-by-design and secure-by-default principles, security requirements, and assurance in software development.
Threat modelling and secure design
Threat modelling approaches, attack surface analysis, trust boundaries, misuse cases, and secure design patterns.
Secure coding and verification
Secure coding practices, OWASP Top 10 and OWASP ASVS, code review, input validation, authentication and authorisation controls, error handling, and secrets management.
Software testing and analysis
Static analysis, dynamic analysis, software composition analysis, fuzzing, dependency and vulnerability management, and remediation workflows.
DevSecOps and software supply chain security
Security in CI/CD pipelines, automation, policy-as-code, container and IaC security, SBOM concepts, package integrity, and open-source component risk.
AI-assisted development and professional practice
Security risks of AI-generated code, governance of AI coding tools, prompt-related risks, hallucinated or insecure code patterns, verification of AI-assisted outputs, and ethical and professional responsibilities.
Assessment strategy and rationale
The assessment strategy is designed to progressively develop students’ capability from analysis to implementation and critical evaluation. Assessment 1 requires students to analyse a software system or scenario using secure SDLC and threat modelling principles, building foundational capability in identifying risks, trust boundaries and security requirements. Assessment 2 then requires students to apply secure coding and verification techniques to implement or improve a software artefact, demonstrating practical skill in secure development, testing and remediation. Assessment 3 requires students to critically evaluate a complex software security scenario involving issues such as software supply chain risk, DevSecOps controls, or AI-assisted development, and justify an appropriate secure engineering response. Together, these assessments provide a coherent progression from analysis to application to advanced evaluation, and support achievement of all learning outcomes. To pass this unit, students must demonstrate competence in all learning outcomes and achieve an aggregate mark of at least 50%.
Overview of assessments
Task 1: Secure design and threat modelling repor...
Task 1: Secure design and threat modelling report
Students analyse a supplied software system, architecture or case scenario and produce a structured threat model and secure design review. They identify assets, trust boundaries, likely threats, security requirements and recommended design controls.
Submission Type: Individual
Assessment Method: Practical task
Artefact: report (1200 words)
25%
Task 2: Applied secure coding and verification t...
Task 2: Applied secure coding and verification task
Students apply secure coding and verification practices to a supplied or student-developed software artefact. They implement or improve controls, conduct appropriate analysis or testing, document vulnerabilities and remediation, and justify the technical decisions made.
Submission Type: Individual
Assessment Method: Presentation
Artefact: 1500 words report plus code and supporting appendix.+ Online Viva
35%
Task 3: Critical software security case analysis...
Task 3: Critical software security case analysis
Students critically evaluate a complex software security scenario involving issues such as insecure dependencies, CI/CD weaknesses, software supply chain compromise, or risks arising from AI-assisted code generation. They justify a secure engineering response for both technical and organisational stakeholders.
Submission Type: Individual
Assessment Method: Presentation
Artefact: Live / Recorded with face-overlay Presentation (7-8 minutes) + Online Viva
40%
Learning and teaching strategy and rationale
This unit is delivered fully online, primarily in an asynchronous mode, through recorded lectures, guided learning resources, practical lab activities, applied coding exercises, case-based learning and discussion forums. Students engage with realistic software development and assurance scenarios to develop secure design, implementation and evaluation skills. Learning activities are structured to support AQF Level 9 learning by requiring analysis of complex technical problems, justification of design decisions, critical evaluation of tools and standards, and reflective consideration of security, risk and responsibility. To further support student learning, up to three optional synchronous online workshops will be offered during the unit for assessment consultation and clarification.
Students should plan to commit approximately 150 hours to this unit over the semester, including participation in learning activities, independent study, readings and assessment preparation.