Перейти к содержимому

ISC2 CISSP - Cybex materials - Chapter20 - Software Development Security

Telman Hajibutayev

0:00 / 0:00

ISC2 CISSP - Cybex materials - Chapter20 - Software Development Security

19 просмотров · 13 дней назад
Telman Hajibutayev
16 подписчиков
19 просмотров · 13 дней назад
Software Development Security THE CISSP EXAM TOPICS COVERED IN THIS CHAPTER INCLUDE: ✓ Domain 3.0: Security Architecture and Engineering ■ 3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements ■ 3.5.3 Database systems ✓ Domain 8.0: Software Development Security ■ 8.1 Understand and integrate security in the Software Development Life Cycle (SDLC) ■ 8.1.1 Development methodologies (e.g., Agile, Waterfall, DevOps, DevSecOps) ■ 8.1.2 Maturity models (e.g., Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM)) ■ 8.1.3 Operation and maintenance ■ 8.1.4 Change management ■ 8.1.5 Integrated Product Team (IPT) ■ 8.2 Identify and apply security controls in software development ecosystems ■ 8.2.1 Programming languages ■ 8.2.2 Libraries ■ 8.2.3 Tool sets ■ 8.2.4 Integrated Development Environment (IDE) ■ 8.2.5 Runtime ■ 8.2.6 Continuous Integration and Continuous Delivery (CI/CD) ■ 8.2.8 Software Configuration Management (SCM) ■ 8.2.9 Code repositories Chapter20 - Software Development Security ■ 8.3 Assess the effectiveness of software security ■ 8.3.1 Auditing and logging of changes ■ 8.4 Assess security impact of acquired software ■ 8.4.1 Commercial- off- the- shelf (COTS) ■ 8.4.2 Open source ■ 8.4.3 Third- party ■ 8.5 Define and apply secure coding guidelines and standards ■ 8.5.2 Security of Application Programming Interfaces (APIs) ■ 8.5.3 Secure coding practices ■ 8.5.4 Software - defined security