CSSLP Cert Prep: 2 Secure Software Requirements
1h 31mIntermediate2021-02-26
Authors

Jerod Brennen
Security Architect, Advisor, Speaker, Teacher
Course details
Specific, achievable security requirements are critical ingredients in the creation of any application. In this course, the second installment in the CSSLP Cert Prep series, instructor Jerod Brennen dives into the subject of security requirements to prepare you for the second domain of the Certified Secure Software Lifecycle Professional (CSSLP) exam: Secure Software Requirements. Jerod discusses how to properly define what an app must be and do in order to remain secure. He covers how to approach security, privacy, and data classification requirements for applications. Plus, he goes over how to validate your requirements, including how to use a security requirement traceability matrix (SRTM) to determine how well an app adheres to your security requirements.
Skills covered
Software Development SecurityCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Determining security requirements
1. Security Requirements
- 02 - Functional requirements
- 03 - Nonfunctional requirements
- 04 - Policy decomposition
- 05 - Legal, regulatory, and industry
2. Privacy Requirements
- 06 - Security vs. privacy
- 07 - Data anonymization
- 08 - User consent
- 09 - Disposition
- 10 - Private data storage
3. Data Classification Requirements
- 11 - Data ownership
- 12 - Labeling
- 13 - Types of data
- 14 - Data life cycle
4. Validating Your Requirements
- 15 - Misuse and abuse cases
- 16 - Software requirement specifications
- 17 - Security requirement traceability matrix
Conclusion
- 18 - Next steps