CISSP Cert Prep (2021): 8 Software Development Security

CISSP Cert Prep (2021): 8 Software Development Security

2h 45mAdvanced2022-02-28

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Are you preparing to take the Certified Information Systems Security Professional (CISSP) exam, or are you a cybersecurity professional pursuing a better understanding of secure coding practices? In this course, instructor Mike Chapple provides you with the detailed information you need to get ready for the Software Development Security domain of the 2021 CISSP exam. Mike explains software development security practices as needed to complete the exam. He covers the software development lifecycle, code review, software testing, and common software security issues. Mike also discusses secure coding practices, security considerations for cloud computing, and software security assessment.

Skills covered

Software Development SecurityIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Software development security
  • What you need to know
  • Study resources

Software Development Lifecycle

  • Software platforms
  • Development methodologies
  • Maturity models
  • Change management
  • Automation and DevOps
  • Programming languages
  • Acquired software

Software Quality Assurance

  • Code review
  • Software testing
  • Code security tests
  • Fuzz testing
  • Code repositories
  • Application management
  • Third-party code
  • Software risk analysis and mitigation

Application Attacks

  • OWASP Top 10
  • Application security
  • Preventing SQL injection
  • Understanding cross-site scripting
  • Request forgery
  • Defending against directory traversal
  • Overflow attacks
  • Explaining cookies and attachments
  • Session hijacking
  • Code execution attacks
  • Privilege escalation
  • Driver manipulation
  • Memory vulnerabiliities
  • Race condition vulnerabilities

Secure Coding Practices

  • Input validation
  • Parameterized queries
  • Authentication session management issues
  • Output encoding
  • Error and exception handling
  • Code signing
  • Database security
  • Data deidentification
  • Data obfuscation

Cloud Computing

  • What is the cloud
  • Cloud computing roles
  • Drivers for cloud computing
  • Security service providers
  • Cloud activities and the cloud reference architecture
  • Cloud deployment models
  • Cloud service categories

Conclusion

  • Continuing your studies
80,000 Toman