ISC2 CISSP - Cybex materials - Chapter20 - Software Development Security
Telman Hajibutayev
0:00 / 0:00
ISC2 CISSP - Cybex materials - Chapter20 - Software Development Security
19 просмотров · 13 дней назад
Telman Hajibutayev
16 подписчиков
19 просмотров · 13 дней назад
Software Development Security
THE CISSP EXAM TOPICS COVERED IN THIS CHAPTER INCLUDE:
✓ Domain 3.0: Security Architecture and Engineering
■ 3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
■ 3.5.3 Database systems
✓ Domain 8.0: Software Development Security
■ 8.1 Understand and integrate security in the Software Development Life Cycle (SDLC)
■ 8.1.1 Development methodologies (e.g., Agile, Waterfall, DevOps, DevSecOps)
■ 8.1.2 Maturity models (e.g., Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM))
■ 8.1.3 Operation and maintenance
■ 8.1.4 Change management
■ 8.1.5 Integrated Product Team (IPT)
■ 8.2 Identify and apply security controls in software development ecosystems
■ 8.2.1 Programming languages
■ 8.2.2 Libraries
■ 8.2.3 Tool sets
■ 8.2.4 Integrated Development Environment (IDE)
■ 8.2.5 Runtime
■ 8.2.6 Continuous Integration and Continuous Delivery (CI/CD)
■ 8.2.8 Software Configuration Management (SCM)
■ 8.2.9 Code repositories
Chapter20 - Software Development Security
■ 8.3 Assess the effectiveness of software security
■ 8.3.1 Auditing and logging of changes
■ 8.4 Assess security impact of acquired software
■ 8.4.1 Commercial- off- the- shelf (COTS)
■ 8.4.2 Open source
■ 8.4.3 Third- party
■ 8.5 Define and apply secure coding guidelines and standards
■ 8.5.2 Security of Application Programming Interfaces (APIs)
■ 8.5.3 Secure coding practices
■ 8.5.4 Software - defined security