CSSLP: Official (ISC)2 Certified Secure Software Lifecycle



Kursarrangør: SG Partner AS
Sted: Nettkurs / Nettstudie
Hele landet
Type:Bedriftsinternt / Større grupper
Nettkurs og nettstudie
Studie / yrkesutdanning
Undervisningstid: Ta kontakt for informasjon
Varighet: 5 dager
Pris: 37.000

We offer virtual course in official (ISC)2 certified secure software lifecycle professional (CSSLP) training included exam.

Course overview:
The official (ISC)²® certified secure software lifecycle professional (CSSLP®) training provides a comprehensive review of the knowledge required to incorporate security practices - authentication, authorization and auditing - into each phase of the software development lifecycle (SDLC), from software design and implementation to testing and deployment. This training course will help students review and refresh their knowledge and identify areas they need to study for the CSSLP exam. Content aligns with and comprehensively covers the eightdomains of the (ISC)² CSSLP common body of knowledge (CBK®).

As an (ISC)2 official training provider, we use courseware developed by (ISC)² - creator of the CSSLPCBK - to ensure your training is relevant and up-to-date. Our instructors are verified security experts who hold the CSSLP and have completed intensive training to teach (ISC)² content.

Please note:
• An exam voucher is included with this course

Course content:
• Domain 1 - Secure software concepts
• Domain 2 - Secure software requirements
• Domain 3 - Secure software architecture and design
• Domain 4 - Secure software implementation
• Domain 5 - Secure software testing
• Domain 6 - Secure lifecycle management
• Domain 7 - Software deployment, operations and maintenance
• Domain 8 - Supply chain

Course objectives:
After completing this course, you should be able to:
• Understand the core concepts of software security and the foundational principles that drive construction of resilient software.
• Recognize the importance of security requirements and understand the techniques for elicitation and specification of software security requirements.
• Recognize privacy requirements and their impact on the selection of safeguards and countermeasures.
• Understand threat modeling, attack surface evaluation, and architectural risk assessment.
• Recognize secure design principles and patterns.
• Understand secure coding practices, common application vulnerabilities and their mitigation strategies.
• Understand various code analysis techniques using automated and manual techniques.

• Recognize risks of third-party software components and libraries, malicious code and mitigation strategies.
• Describe security testing strategy and techniques and identify functional and non-functional testing methods.
• Describe defect tracking and risk scoring methods.
• Identify secure software methodologies, standards and frameworks.
• Understand governance, risk, and compliance and recognize regulations and compliance requirements.
• Describe risks during deployment and understand security relevant issues during the operations and maintenance phase of the lifecycle.
• Understand vulnerability management, security monitoring, incident response, and root cause analysis.
• Recognize software supply chain risks and attacks.

Target audience:
This training course is intended for professionals who have at least four years of cumulative, paid work experience as a software development lifecycle professional in one or more of the eight domains of the (ISC)2 CSSLP CBK. The course builds on and brings together the holistic view of the topics covered in the everyday environment of an information assurance professional.

Prerequisites:
Attendees should meet the following prerequisites:
• Have at least four years of cumulative, paid work experience as a software development lifecycle professional in one or more of the eight domainsof the (ISC)2 CSSLP CBK.

Test certification:
Recommended as preparation for the following exam:
• (ISC)2 Certified secure software lifecycle professional

A candidate is required to have a minimum of four years cumulative paid full-time software development lifecycle (SDLC) professional work experience in one or more of the eight domains of the (ISC)2 CSSLP CBK, or three years of cumulative paid full-time SDLC professional work experience in one or more of the eight domains of the CSSLP CBK with a four -year degree leading to a baccalaureate, or regional equivalent in computer science, information technology (IT) or related fields.

A candidate that doesn’t have the required experience to become a CSSLP may become an associate of (ISC)² by successfully passing the CSSLP examination. The associate of (ISC)² will then have 5 years to earn the 4 years required experience.