A management discipline for security debt, borrowed directly from the technical debt concept: a known, accepted gap between the current security state and the fully remediated state that an organisation has consciously chosen not to close immediately. Covers why tracked debt is more manageable than the same gap left implicit and untracked, the boundary that separates genuine debt from an unknown vulnerability and from an active, unacceptable exposure the metaphor should never normalise, the three major sources this catalogue's other courses already produce evidence of, accepted risk exceptions, end of life components and lower priority findings, the case for tracking every source in one consolidated register, interest accrual as the framing that separates compounding debt from stable debt, budgeting a deliberate share of every engineering cycle for paydown, prioritising which debt to pay down first, common paydown programme failure modes, and reporting security debt to leadership as a quantified, trending metric using a clearly labelled hypothetical dataset.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.