Secure Software Prerequisites (14%):
- Recognize and evaluate compliance prerequisites;
- Recognize and evaluate data classification prerequisites, including data ownership, data types, labeling, and data lifecycle;
- Recognize and evaluate privacy prerequisites, including data anonymization, data retention, user consent, cross borders, and disposition;
- Ensure security prerequisites flow down to providers/suppliers.
- Develop abuse and misuse cases;
- Explain software security prerequisites, including functional and non-functional;
- Establish security prerequisite traceability matrix;
Secure Software Design & Architecture (14%):
- Carry out security design and architecture review;
- Model security properties and limitations;
- Utilize secure design and architecture principles, tools, and patterns.
- Carry out secure interface design, including security management interfaces, log interfaces, and Out-of-Band management;
- Model the data and classify it;
- Explain secure operation architecture such as the operational interfaces and deployment topology;
- Carry out threat modeling – This area covers an understanding of common threats, threat intelligence, and attack surface evaluation;
- Explain security architectures – The subtopic evaluates your skills in working with the Cloud architecture, hardware platform concerns, control systems, cognitive computing, rich Internet applications, embedded, distributed computing, and service-oriented architecture;
- Measure and analyze the reusable secure design, including credential management, data loss prevention, trusted computing, virtualization, programming language environment, database security, flow control, as well as operating system services and controls;
ISC CSSLP Exam Overview:
| Certification Vendor: | (ISC)² |
|---|---|
| Exam Name: | Certified Secure Software Lifecycle Professional Exam |
| Exam Number: | CSSLP |
| Related Certifications: | SSCP CCSP CISSP |
| Exam Price: | $599 USD |
| Exam Format: | Advanced item types, Multiple-choice |
| Available Languages: | English |
| Real Exam Qty: | 125 |
| Exam Duration: | 180 minutes |
| Certificate Validity Period: | 3 years |
| Passing Score: | 700 out of 1000 |
| Recommended Training: | CSSLP Self-Study Resources Official ISC2 CSSLP Training |
| Exam Registration: | Pearson VUE Testing (ISC)² Official Registration |
| Sample Questions: | ISC CSSLP Sample Questions |
| Exam Way: | In-person at Pearson VUE testing centers or online proctored |
| Pre Condition: | 4 years of cumulative paid work experience in 1 or more CSSLP domains; 3 years with a bachelor's degree; CISSP holders are exempt from work experience requirement |
| Official Syllabus URL: | https://www.isc2.org/certifications/csslp/csslp-certification-exam-outline |
Secure Software Supply Chain (11%):
- Implement risk management for the software supply chain – This part includes identifying, assessing, responding, and monitoring;
- Support contractual prerequisites, including intellectual property ownership, end-user license agreement, warranty, code escrow, service level agreement, and liability.
- Validate provenance and pedigree – It covers secure transfer, code repository security, right to audit, system interconnection/sharing, cryptographically-hashed & digitally-signed elements, and developing environmental security;
- Ensure security prerequisites of the supplier within the acquisition process – This section measures your knowledge of security track record, maintenance & support structure, and security policy compliance audit;
- Evaluate security of the 3rd-party software;
ISC CSSLP Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Secure Software Implementation | 14% | - Static analysis and code review - Cryptography usage - Input validation & output encoding - Secure coding standards |
| Secure Software Testing | 14% | - Static and dynamic application testing - Security testing strategy - Vulnerability verification - Penetration testing |
| Secure Software Lifecycle Management | 11% | - SDLC methodologies integration - Environment and tool security - Security governance and metrics - Configuration and change management |
| Secure Software Architecture and Design | 15% | - Secure design for platforms - Attack surface reduction - Threat modeling methodologies - Security architecture patterns |
| Secure Software Supply Chain | 10% | - Third-party component security - Supplier risk assessment - Software bill of materials - Supply chain attack mitigation |
| Secure Software Concepts | 12% | - Security policies and compliance - Core security principles - Risk management fundamentals - Security design principles |
| Secure Software Requirements | 13% | - Misuse and abuse case analysis - Compliance and privacy requirements - Requirements traceability - Security requirements elicitation |
| Secure Software Deployment, Operations and Maintenance | 11% | - Operational security monitoring - Secure deployment and configuration - Secure decommissioning - Patch and vulnerability management |

We're so confident of our products that we provide no hassle product exchange.


By Lillian


