ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep

ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep

13h 43mIntermediate2024-06-25

Authors

Jerod Brennen

Jerod Brennen

Security Architect, Advisor, Speaker, Teacher

Course details

The Certified Secure Software Lifecycle Professional (CSSLP) certification is designed for software development and security professionals, including software architects, developers, project managers, security managers, quality assurance testers, and anyone responsible for ensuring the security of software applications throughout the development lifecycle. This comprehensive course with instructor Jerod Brennen helps you prepare to tackle the official CSSLP exam. Explore the core concepts and fundamental skills required for each of the eight domains of the exam: Secure Software Concepts; Secure Software Lifecycle Management; Secure Software Requirements; Secure Software Architecture and Design; Secure Software Implementation; Secure Software Testing; Software Deployment, Operations, and Maintenance; and Secure Software Supply Chain.

Skills covered

Software Development SecuritySoftware ArchitectureCert PrepCybersecuritySoftware Development

Concepts

Introduction

  • Prepping for the CSSLP

Domain 1 - Secure Software Concepts

  • Secure software concepts
  • What you should know
  • The goals of application security

The CIA Triad

  • Confidentiality
  • Integrity
  • Availability

Identity and Access Management

  • Authentication
  • Authorization
  • Accountability
  • Nonrepudiation
  • Governance, risk, and compliance

Access Controls

  • Least privilege
  • Separation of duties
  • Economy of mechanism
  • Complete mediation

Design Considerations

  • Defense in depth
  • Resiliency
  • Open design
  • Least common mechanism
  • Psychological acceptability
  • Leveraging existing components
  • Eliminate single point of failure
  • Diversity of defense

Domain 2 - Secure Software Lifecycle Management

  • Secure software lifecycle management

Laying Your Foundation

  • Strategy and roadmap
  • Development methodologies
  • Integrated risk management
  • Promote security culture

Setting Expectations

  • Security standards and frameworks
  • Security documentation
  • Hardware and software configuration
  • Ongoing configuration management

Improving Over Time

  • Decommission software
  • Manage licenses and archives
  • Security metrics
  • Reporting security status
  • Continuous improvement
  • Implement secure operations practices

Domain 3 - Secure Software Requirements

  • Determining security requirements

Security Requirements

  • Functional requirements
  • Nonfunctional requirements
  • Policy decomposition
  • Legal, regulatory, and industry

Privacy Requirements

  • Security vs. privacy
  • Data anonymization
  • User consent
  • Disposition
  • Private data storage

Data Classification Requirements

  • Data ownership
  • Labeling
  • Types of data
  • Data lifecycle

Validating Your Requirements

  • Misuse and abuse cases
  • Software requirement specifications
  • Security requirement traceability matrix

Domain 4 - Secure Software Architecture and Design

  • Secure software design

Threat Modeling

  • What is threat modeling
  • Understand common threats
  • Attack surface evaluation

Security Architecture

  • Secure architecture and design patterns
  • Identifying and prioritizing controls
  • Traditional application architectures
  • Pervasive and ubiquitous computing
  • Rich internet and mobile applications
  • Cloud architectures
  • Embedded system considerations
  • Architectural risk assessments
  • Component-based systems
  • Security enhancing tools
  • Cognitive computing
  • Control systems

Security Design

  • Components of a secure environment
  • Designing network and server controls
  • Designing data controls
  • Secure design principles and patterns
  • Secure interface design
  • Security architecture and design review
  • Secure operational architecture

Modeling

  • Nonfunctional properties and constraints
  • Data modeling and classification

Domain 5 - Secure Software Implementation

  • Secure software implementation

Secure Coding Practices

  • Declaring variables
  • Inputs and outputs
  • Protecting secrets
  • Data-flow security
  • Deployment and operations
  • Isolation techniques
  • Processor microarchitecture security

Finding and Fixing Vulnerabilities

  • Identifying risks
  • The OWASP Top 10 - 1-5
  • The OWASP Top 10 - 6-10
  • Common Weakness Enumeration (CWE)
  • Addressing risks

Component Security

  • Third-party code and libraries
  • Component integration
  • Implementing security controls
  • Security in the build process

Domain 6 - Secure Software Testing

  • Secure software testing

Developing Security Test Cases

  • Understanding your test environment
  • Automation vs. manual testing
  • Ensuring a comprehensive approach
  • Validating cryptography

Developing a Testing Strategy

  • Grouping your tests
  • Leveraging external resources
  • Verifying and validating documentation

Conducting Security Tests

  • Securing test data
  • Verification and validation testing
  • Identifying undocumented functionality

Reviewing the Results

  • Security implications of test results
  • Classifying and tracking security errors

Domain 7 - Secure Software Deployment, Operations, and Maintenance

  • Secure software deployment, operations, and maintenance

Deploying Your Software

  • Performing an operational risk analysis
  • Releasing software securely
  • Storing and managing security data
  • Ensuring secure installation
  • Post-deployment security testing

Shifting Into Operations

  • Obtaining security approval to operate
  • Continuous security monitoring
  • Support incident response
  • Support continuity of operations
  • Service level objectives and agreements

Maintaining Your Software

  • Patch management
  • Vulnerability management
  • Runtime protection

Domain 8 - Secure Software Supply Chain

  • Secure software supply chain

Supply Chain Risk Management

  • Identifying and selecting components
  • Assessing components' risks
  • Responding to those risks
  • Monitoring changes and vulnerabilities
  • Maintaining third-party components

Ensure Software Security

  • Analyzing third-party software security
  • Verifying pedigree and provenance

Get It in Writing

  • Security in the acquisition process
  • Contractual requirements

Exam Logistics

  • Registering for the exam
  • Exam environment
  • Passing the exam
  • Exam tips
  • Practice tests
  • Experience requirements
  • Continuing education requirements

Conclusion

  • Next steps
200,000 Toman