Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep

ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep

13h 43mIntermediate2024-06-25

Authors

Jerod Brennen

Jerod Brennen

Security Architect, Advisor, Speaker, Teacher

Course details

The Certified Secure Software Lifecycle Professional (CSSLP) certification is designed for software development and security professionals, including software architects, developers, project managers, security managers, quality assurance testers, and anyone responsible for ensuring the security of software applications throughout the development lifecycle. This comprehensive course with instructor Jerod Brennen helps you prepare to tackle the official CSSLP exam. Explore the core concepts and fundamental skills required for each of the eight domains of the exam: Secure Software Concepts; Secure Software Lifecycle Management; Secure Software Requirements; Secure Software Architecture and Design; Secure Software Implementation; Secure Software Testing; Software Deployment, Operations, and Maintenance; and Secure Software Supply Chain.

Skills covered

Software Development SecuritySoftware ArchitectureCybersecurityCert PrepSoftware Development

Concepts

0. Introduction

  • 01 - Prepping for the CSSLP

1. Domain 1 - Secure Software Concepts

  • 02 - Secure software concepts
  • 03 - What you should know
  • 04 - The goals of application security

2. The CIA Triad

  • 05 - Confidentiality
  • 06 - Integrity
  • 07 - Availability

3. Identity and Access Management

  • 08 - Authentication
  • 09 - Authorization
  • 10 - Accountability
  • 11 - Nonrepudiation
  • 12 - Governance, risk, and compliance

4. Access Controls

  • 13 - Least privilege
  • 14 - Separation of duties
  • 15 - Economy of mechanism
  • 16 - Complete mediation

5. Design Considerations

  • 17 - Defense in depth
  • 18 - Resiliency
  • 19 - Open design
  • 20 - Least common mechanism
  • 21 - Psychological acceptability
  • 22 - Leveraging existing components
  • 23 - Eliminate single point of failure
  • 24 - Diversity of defense

6. Domain 2 - Secure Software Lifecycle Management

  • 25 - Secure software lifecycle management

7. Laying Your Foundation

  • 26 - Strategy and roadmap
  • 27 - Development methodologies
  • 28 - Integrated risk management
  • 29 - Promote security culture

8. Setting Expectations

  • 30 - Security standards and frameworks
  • 31 - Security documentation
  • 32 - Hardware and software configuration
  • 33 - Ongoing configuration management

9. Improving Over Time

  • 34 - Decommission software
  • 35 - Manage licenses and archives
  • 36 - Security metrics
  • 37 - Reporting security status
  • 38 - Continuous improvement
  • 39 - Implement secure operations practices

10. Domain 3 - Secure Software Requirements

  • 40 - Determining security requirements

11. Security Requirements

  • 41 - Functional requirements
  • 42 - Nonfunctional requirements
  • 43 - Policy decomposition
  • 44 - Legal, regulatory, and industry

12. Privacy Requirements

  • 45 - Security vs. privacy
  • 46 - Data anonymization
  • 47 - User consent
  • 48 - Disposition
  • 49 - Private data storage

13. Data Classification Requirements

  • 50 - Data ownership
  • 51 - Labeling
  • 52 - Types of data
  • 53 - Data lifecycle

14. Validating Your Requirements

  • 54 - Misuse and abuse cases
  • 55 - Software requirement specifications
  • 56 - Security requirement traceability matrix

15. Domain 4 - Secure Software Architecture and Design

  • 57 - Secure software design

16. Threat Modeling

  • 58 - What is threat modeling
  • 59 - Understand common threats
  • 60 - Attack surface evaluation

17. Security Architecture

  • 61 - Secure architecture and design patterns
  • 62 - Identifying and prioritizing controls
  • 63 - Traditional application architectures
  • 64 - Pervasive and ubiquitous computing
  • 65 - Rich internet and mobile applications
  • 66 - Cloud architectures
  • 67 - Embedded system considerations
  • 68 - Architectural risk assessments
  • 69 - Component-based systems
  • 70 - Security enhancing tools
  • 71 - Cognitive computing
  • 72 - Control systems

18. Security Design

  • 73 - Components of a secure environment
  • 74 - Designing network and server controls
  • 75 - Designing data controls
  • 76 - Secure design principles and patterns
  • 77 - Secure interface design
  • 78 - Security architecture and design review
  • 79 - Secure operational architecture

19. Modeling

  • 80 - Nonfunctional properties and constraints
  • 81 - Data modeling and classification

20. Domain 5 - Secure Software Implementation

  • 82 - Secure software implementation

21. Secure Coding Practices

  • 83 - Declaring variables
  • 84 - Inputs and outputs
  • 85 - Protecting secrets
  • 86 - Data-flow security
  • 87 - Deployment and operations
  • 88 - Isolation techniques
  • 89 - Processor microarchitecture security

22. Finding and Fixing Vulnerabilities

  • 90 - Identifying risks
  • 91 - The OWASP Top 10 - 1-5
  • 92 - The OWASP Top 10 - 6-10
  • 93 - Common Weakness Enumeration (CWE)
  • 94 - Addressing risks

23. Component Security

  • 95 - Third-party code and libraries
  • 96 - Component integration
  • 97 - Implementing security controls
  • 98 - Security in the build process

24. Domain 6 - Secure Software Testing

  • 99 - Secure software testing

25. Developing Security Test Cases

  • 100 - Understanding your test environment
  • 101 - Automation vs. manual testing
  • 102 - Ensuring a comprehensive approach
  • 103 - Validating cryptography

26. Developing a Testing Strategy

  • 104 - Grouping your tests
  • 105 - Leveraging external resources
  • 106 - Verifying and validating documentation

27. Conducting Security Tests

  • 107 - Securing test data
  • 108 - Verification and validation testing
  • 109 - Identifying undocumented functionality

28. Reviewing the Results

  • 110 - Security implications of test results
  • 111 - Classifying and tracking security errors

29. Domain 7 - Secure Software Deployment, Operations, and Maintenance

  • 112 - Secure software deployment, operations, and maintenance

30. Deploying Your Software

  • 113 - Performing an operational risk analysis
  • 114 - Releasing software securely
  • 115 - Storing and managing security data
  • 116 - Ensuring secure installation
  • 117 - Post-deployment security testing

31. Shifting Into Operations

  • 118 - Obtaining security approval to operate
  • 119 - Continuous security monitoring
  • 120 - Support incident response
  • 121 - Support continuity of operations
  • 122 - Service level objectives and agreements

32. Maintaining Your Software

  • 123 - Patch management
  • 124 - Vulnerability management
  • 125 - Runtime protection

33. Domain 8 - Secure Software Supply Chain

  • 126 - Secure software supply chain

34. Supply Chain Risk Management

  • 127 - Identifying and selecting components
  • 128 - Assessing components' risks
  • 129 - Responding to those risks
  • 130 - Monitoring changes and vulnerabilities
  • 131 - Maintaining third-party components

35. Ensure Software Security

  • 132 - Analyzing third-party software security
  • 133 - Verifying pedigree and provenance

36. Get It in Writing

  • 134 - Security in the acquisition process
  • 135 - Contractual requirements

37. Exam Logistics

  • 136 - Registering for the exam
  • 137 - Exam environment
  • 138 - Passing the exam
  • 139 - Exam tips
  • 140 - Practice tests
  • 141 - Experience requirements
  • 142 - Continuing education requirements

Conclusion

  • 143 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal