Certified Secure Software Lifecycle Professional (CSSLP)
(CSSLP.AO1) / ISBN : 978-1-64459-229-8
Über diesen Kurs
Fähigkeiten, die Sie erwerben werden
Unterricht
21+ Unterricht | 299+ Tests | 236+ Karteikarten | 236+ Glossar der Begriffe
Testvorbereitung
100+ Fragen vor der Beurteilung | 2+ Ausführliche Tests | 100+ Fragen nach der Bewertung | 200+ Testfragen zur Praxis
Introduction
- Why Focus on Software Development?
- The Role of CSSLP
- How to Use This Course?
- The Examination
- CSSLP (2020)
General Security Concepts
- General Security Concepts
- Security Models
- Adversaries
- Lesson Review
Risk Management
- Definitions and Terminology
- Types of Risk
- Governance, Risk, and Compliance
- Risk Management Models
- Risk Options
- Lesson Review
Security Policies and Regulations
- Regulations and Compliance
- Legal Issues
- Privacy
- Security Standards
- Secure Software Architecture
- Trusted Computing
- Acquisition
- Lesson Review
Software Development Methodologies
- Secure Development Lifecycle
- Secure Development Lifecycle Components
- Software Development Models
- Microsoft Security Development Lifecycle
- Lesson Review
Policy Decomposition
- Confidentiality, Integrity, and Availability Requirements
- Authentication, Authorization, and Auditing Requirements
- Internal and External Requirements
- Lesson Review
Data Classification and Categorization
- Data Classification
- Data Ownership
- Labeling
- Types of Data
- Data Lifecycle
- Lesson Review
Requirements
- Functional Requirements
- Operational Requirements
- Requirements Traceability Matrix
- Connecting the Dots
- Lesson Review
Design Processes
- Attack Surface Evaluation
- Threat Modeling
- Control Identification and Prioritization
- Risk Assessment for Code Reuse
- Documentation
- Design and Architecture Technical Review
- Lesson Review
Design Considerations
- Application of Methods to Address Core Security Concepts
- Interfaces
- Lesson Review
Securing Commonly Used Architecture
- Distributed Computing
- Service-Oriented Architecture
- Rich Internet Applications
- Pervasive/Ubiquitous Computing
- Mobile Applications
- Integration with Existing Architectures
- Cloud Architectures
- Lesson Review
Technologies
- Authentication and Identity Management
- Credential Management
- Flow Control (Proxies, Firewalls, Middleware)
- Logging
- Data Loss Prevention
- Virtualization
- Digital Rights Management
- Trusted Computing
- Database Security
- Programming Language Environment
- Operating Systems
- Embedded Systems
- Lesson Review
Common Software Vulnerabilities and Countermeasures
- CWE/SANS Top 25 Vulnerability Categories
- OWASP Vulnerability Categories
- Common Vulnerabilities and Countermeasures
- Input Validation Failures
- Common Enumerations
- Virtualization
- Embedded Systems
- Side Channel
- Social Engineering Attacks
- Lesson Review
Defensive Coding Practices
- Declarative vs. Programmatic Security
- Memory Management
- Error Handling
- Interface Coding
- Primary Mitigations
- Learning from Past Mistakes
- Lesson Review
Secure Software Coding Operations
- Code Analysis (Static and Dynamic)
- Code/Peer Review
- Build Environment
- Antitampering Techniques
- Configuration Management: Source Code and Versioning
- Lesson Review
Security Quality Assurance Testing
- Standards for Software Quality Assurance
- Testing Methodology
- Functional Testing
- Security Testing
- Environment
- Bug Tracking
- Attack Surface Validation
- Testing Artifacts
- Test Data Lifecycle Management
- Lesson Review
Security Testing
- Scanning
- Penetration Testing
- Fuzzing
- Simulation Testing
- Testing for Failure
- Cryptographic Validation
- Regression Testing
- Impact Assessment and Corrective Action
- Lesson Review
Secure Lifecycle Management
- Introduction to Acceptance
- Pre-release Activities
- Post-release Activities
- Lesson Review
Secure Software Installation and Deployment
- Secure Software Installation and Its Subsequent Deployment
- Configuration Management
- Lesson Review
Secure Software Operations and Maintenance
- Secure Software Operations
- The Software Maintenance Process
- Secure DevOps
- Secure Software Disposal
- Lesson Review
Supply Chain and Software Acquisition
- Supplier Risk Assessment
- Supplier Sourcing
- Software Development and Testing
- Software Delivery, Operations, and Maintenance
- Supplier Transitioning
- Lesson Review
General Security Concepts
- Understanding Security Design Tenets
- Discussing About Access Control Models
- Understanding Information Flow Models
Risk Management
- Understanding Annualized Loss Expectancy
Security Policies and Regulations
- Understanding Compliance-Based Assessment Regulations
- Understanding PII and PHI
- Understanding National Institute of Standards and Technology
Software Development Methodologies
- Discussing About Software Development Methodologies
- Understanding Secure Development Lifecycle Components
- Understanding Software Development Models
Policy Decomposition
- Understanding Access Control Mechanisms
Data Classification and Categorization
- Understanding Data Classification Types
- Understanding Data Ownership Roles
Requirements
- Understanding Functional Requirements
- Understanding the Requirements Traceability Matrix
Design Processes
- Understanding Documentation
Design Considerations
- Discussing About Security Design Considerations
Securing Commonly Used Architecture
- Understanding Distributed Computing Terms
- Understanding the Enterprise Service Bus
- Understanding Cloud Service Models
Technologies
- Understanding X.509 Digital Certificate Fields
- Understanding Flow Control Technologies
- Understanding Syslog
- Understanding Trusted Computing Elements
Common Software Vulnerabilities and Countermeasures
- Discussing About Software Vulnerabilities and Countermeasures
- Understanding the Buffer Overflow Attack
Defensive Coding Practices
- Understanding Imperative and Declarative Securities
- Understanding Memory Management
Secure Software Coding Operations
- Understanding Code Analysis Types
Security Quality Assurance Testing
- Discussing About Security Quality Assurance Testing Methods
- Understanding Functional Testing Types
- Understanding Security Testing Types
Security Testing
- Understanding the Attack Surface Analyzer
- Understanding Regression Testing
Secure Lifecycle Management
- Understanding Various Forms of Testing
Secure Software Installation and Deployment
- Understanding Bootstrapping
Secure Software Operations and Maintenance
- Understanding Operations/Maintenance Activities
- Understanding the Software Disposal Process
Supply Chain and Software Acquisition
- Discussing About Supplier Risk Assessment
- Understanding Service Level Agreements
Haben Sie Fragen? Schauen Sie sich die FAQs an
Sie haben noch unbeantwortete Fragen und möchten Kontakt aufnehmen?
Kontaktiere uns jetztEUR 599
Preise und Steuern können von Land zu Land unterschiedlich sein.
Multiple-Choice-Fragen
Ein Kandidat muss über mindestens vier Jahre kumulative bezahlte Berufserfahrung im Software Development Lifecycle (SDLC) in einem oder mehreren der acht Bereiche des (ISC)2 CSSLP CBK oder drei Jahre kumulative bezahlte Berufserfahrung im SDLC in einem oder mehreren der acht Bereiche des CSSLP CBK mit einem vierjährigen Abschluss mit Bachelor-Abschluss oder einem regionalen Äquivalent in Informatik, Informationstechnologie (IT) oder verwandten Bereichen verfügen.
Die Prüfung umfasst 125 Fragen.
180 Minuten
700
Hier sind die Richtlinien für die Wiederholung:
- Sollten Sie die Prüfung nicht beim ersten Anlauf bestehen, können Sie diese nach 30 Tagen wiederholen.
- Bei Nichtbestehen des zweiten Anlaufs ist eine Wiederholung der Prüfung nach weiteren 90 Tagen möglich.
- Wenn Sie ein drittes Mal nicht bestehen, können Sie die Prüfung 180 Tage nach Ihrem letzten Prüfungsversuch wiederholen.
Drei Jahre