This is the content of Software development security of CISSP®

This domain 8 is worth 10% of the grade to be achieved.

Domaine 8 of CISSP®

Content updated according to the new official programme for 2024

Description
8.1Understandand 0 Igrate security in the Software Development Life Cycle (SDLC)
8.1.1Development methodologies (eg, Agile, Waterfall,DevOps,DevSecOps)
8.1.2Maturity Models (eg, Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM))
8.1.3Operation and maintenance
8.1.4Change management
8.1.5Integrated Product Team (IPT)
8.2Identify and apply security controls in software development ecosystems
8.2.1Programming languages
8.2.2Libraries
8.2.3Tool sets
8.2.4Integrated Development Environment (IDE)
8.2.5Runtime
8.2.6Continuous Integration and Continuous Delivery (CI/CD)
8.2.7Security Orchestration, Automation, and Response(SOAR)
8.2.8Software Configuration Management (SCM)
8.2.9Code repositories
8.2.10Application security testing (eg, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST)
8.3Assess the effectiveness of software security
8.3.1Auditing And logging of changes
8.3.2Risk analysis and mitigation
8.4Assess security impact of acquired software
8.4.1Commercial-off-the-shelf (COTS)
8.4.2Open source
8.4.3Third-party
8.4.4Managed services (eg, Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS))
8.5Define and apply secure coding guidelines and standards
8.5.1Security weaknesses and vulnerabilities at theSource-code level
8.5.2Security of Application Programming Interfaces (APIs)
8.5.3Secure coding practices
8.5.4Software-defined Security

Ready to Start?