
Explore the CSSLP crash course, an introduction to the certified secure software lifecycle professional exam with a structured, objective-based breakdown, demos, test tips, and practice questions to boost exam readiness.
Discover course requirements for the csslp crash course, designed for information technology professionals with a basic security foundation, focusing on the software development lifecycle, exam prerequisites, and study resources.
Explore CSSLP's focus on secure software development across the lifecycle, with exam formats aligned to CIA SSP, highlighting issue identification before production, testing, standards, and metrics, validated at Pearson VUE.
Department of Defense Directive 8570 stipulates that personnel performing Information Assurance (IA) functions within the DoD must obtain (and maintain) one of the certifications required for their position category or specialty and level.
Learn csslp exam logistics: 175 questions, multiple- or single-choice, proctored at Pearson VUE centers. Targets software-centric professionals such as architects, engineers, developers, security specialists, program managers, and pen testers.
Course content as of 01/06/2020
Explore the CIA triad—confidentiality, integrity, and availability—along with authentication, authorization, accountability, and non-repudiation, foundational concepts in the secure software lifecycle.
Explore the CIA triad—confidentiality, integrity, and availability—and learn how encryption, file permissions, logging, and high availability protect data from unauthorized access and disruption.
Learn non repudiation by identifying who is performing actions and proving administrator authority while tracking who does what and when, using digital signatures and open authentication in e commerce contexts.
Master authentication and authorization, from passwords, multi-factor authentication, and biometrics to access control; learn that authentication precedes authorization and accountability with logging and traceable actions.
Explore core security design principles, including least privilege, separation of duties, defense in depth, complete mediation, open design, and elimination of a single point of failure.
Master the principle of least privilege by granting the right level of privileges to the right user at the right time, to reduce data leaks and footprint and ensure compliance.
Implement separation of duties to reduce fraud and identify breaches by two to three authorized individuals performing key tasks within internal controls and compartmentalization.
Implement defense in depth as a layered approach to IT security across all infrastructure levels, applying physical, technical, and administrative controls to protect applications, services, and data.
Explore defense in depth by outlining layered security across network architecture, interconnection strategy, on-prem and cloud resources, and diverse user contexts for secure deployment.
Explore fail safe and fail secure design, exception management, and how to minimize damage when transactions are interrupted, balancing security, access, and availability in secure software lifecycles.
Learn how open design and peer review foster collaboration, reduce risk, and strengthen security through faster flaw detection, training, and organizational efficiencies, while studying Kirchhoff’s law and foundational cryptography concepts.
Explore the least common mechanism to prevent widespread outages by enforcing isolation and redundancy, ensuring high availability and business continuity across LDAP, SSH concentrators, and cloud VMs.
Explore psychological acceptability in secure software design by balancing usable authentication and robust security controls for users and stakeholders, from login challenges to data center controls.
Learn to leverage existing components to minimize attack surface and footprint by reusing tested versions of directories, WordPress, Linux, and Amazon machine images.
Identify and eliminate single points of failure by designing resilient, scalable applications with load balancing, auto scaling, and fault tolerance, preparing for disasters and outages.
Discover how hashing acts as a one-way function converting plaintext into a fixed message digest, changing output with any input modification, and how nonces add complexity.
Explore fail safe versus fail secure concepts, defense in depth across technical, administrative, and physical controls, and how hashing, digital signatures, and wildcard certificates support secure software lifecycles.
Identify security requirements for software, including functional versus non-functional needs. Explore privacy, data classification, compliance, misuse concepts, and security in specifications via traceability.
Master key terminology for the secure software lifecycle, including roles and users, objects, and the subject–object–activity matrix. Examine use cases, abuse cases, access controls, and logging for threat mitigation.
Identify secure software requirements across layers and the stack, including web and REST API apps, and plan network architecture, services, load balancing, endpoints, and monitoring to defend.
Define operational requirements for deploying software in an enterprise and its interaction with enterprise integration, while following secure coding practices as a repository of vendor standards to reduce customizations.
Explore secure coding references from Carnegie Mellon and the OWASP quick reference guide to validate data, encode outputs, and prepare for the CSSLP exam.
Explore sequencing as the timing and processing approach for command code and byte structures, including inputs and outputs. Examine memory-based recounts, local value increments, and potential race conditions and vulnerabilities.
Define intellectual property and differentiate industrial property, patents, copyrights, trademarks, and trade secrets while clarifying warranties and privacy considerations.
Define privacy per ISC 2, analyze data collection, protection in transit and storage, and assess who may access data, rights to be forgotten, privacy policies, and PPI, cookies, and geolocation.
Learn how to classify and apply preventative, detective, corrective, recovery, deterrents, and compensating controls across administrative, technical, and physical domains, with examples like least privilege, firewalls, encryption, antivirus, and backups.
Learn to interpret data classification requirements. Explore data ownership, labeling, data types, and the data lifecycle.
Master data classification as a risk management tool by defining data ownership, applying labeling for sensitivity, and understanding data types and lifecycle to protect privacy and compliance.
Identify privacy requirements by focusing on data anonymization, user consent, and disposition, and understand how data is handled.
Identify privacy requirements and apply data anonymization techniques such as scrubbing and masking to protect PII, while implementing consent controls and privacy impact assessments.
Explore the maturity model, with a focus on level 1 safe code, and learn safe code resources like the principles for Software Assurance assessment and tactical threat modeling.
Identify threats from any source that could affect enterprise apps or privacy, and implement controls such as intrusion detection system, logging, and plans to address patches and untrained users.
Visualize an application's environment through threat models, identifying threats and security requirements in the SDL lifecycle. Use diagrams and attack trees to plan design analysis, testing, and authentication before coding.
Discover essential standards from NIST, ISO, and IEC that shape secure software lifecycle practices, including ISO/IEC 27001/27002 and PCI guidance.
Explore the objective and basics of the security requirement traceability matrix, learn how to develop an SRTM, and identify the controls involved.
Develop a security requirement traceability matrix (SRTM) to track functional and non-functional requirements, sources, testing, audit records, and controls across design development and implementation, with a NIST 800-53 example.
Learn Safecode principles and core practices for secure software development, explore tactical threat modeling, and review the Safecode publication referenced for the CSSLP exam.
Master CSSLP test tips by reviewing administrative, technical, and physical controls; abuse versus misuse cases; privacy techniques for PII; and industrial versus artistic intellectual property, including trademark, ISO PCI references.
Learn secure software design through threat modeling, security architecture decisions for cloud, distributed, and mobile environments, in-band or out-of-band interfaces, risk assessment, non-functional properties, data classification, modules, and credential management.
Learn to perform threat modeling by identifying threat types, including malware, evaluate the attack surface, and pinpoint areas where threats could impact your application.
Identify common threats such as viruses, malware, phishing, botnets, and denial of service from networks and servers. Patch appropriately, secure protocols, and train users to reduce exposure.
Identify common threats, map attacker methods, and apply threat modeling to document threats in a spreadsheet and plan countermeasures and threat assessments for an enterprise application.
Explore common threat models, including stride, pasta, and vast, and catalog threats, assess attacker goals, and visualize risk to make enterprise-ready software.
Explore threat trees, or attack trees, as diagrams that map system dependencies and identify vulnerabilities, possible attacks, and techniques from dos to sql injection.
Explore how to map threats with an attack tree to model attack methods, access types, devices, and services, identify weaknesses, attacker motivations, and potential controls.
Discover key terminology for secure software lifecycles, including threat intelligence, risk assessment, and mitigation capabilities. Learn how to use threat intelligence platforms, assess baselines, and apply four risk mitigation approaches.
Define the security architecture by identifying how to control and prioritize qualitative and quantitative checks across distributed computing, platform as a service, and mobile apps, shaping security posture.
Explore how security controls differ by architecture, from peer-to-peer encryption and hashing to client-server request validation. Design appropriate controls; firewalls, authentication, authorization, and role B security to reduce enterprise risk.
Show how the enterprise service bus relays messages between services, routing traffic and choosing the right protocol. Describe the security manager handling authentication, authorization, and proxying to enforce safe communication.
Explore rich internet apps, their desktop-like web experience, and the security challenges of remote code execution; learn to apply sandboxed permissions, input validation, and code signing to reduce risks.
Examine cloud architectures and security across public, private, community, and hybrid deployments, and SaaS, PaaS, and IaaS service models, and learn what the provider handles versus what you must manage.
Design secure cloud architectures by mapping on-prem and cloud connections, evaluating provider api support (rest api), and planning how employees and customers access services using mobile apps.
Discover cloud security best practices for Google Cloud Platform, focusing on organizational setup, identities and access management, roles, networking, audit trails, and logging for compliance.
Explore mobile app security within the enterprise, covering threat modeling, mobile device management, policy enforcement, patch management, transitive trust, bring-your-own-device scenarios, and securing perimeter networks.
Navigate hardware platform concerns across RFID, GPS, near-field communication, and Bluetooth, outlining passive tag risks, eavesdropping, rogue access points, and best practices for secure enterprise deployment.
Explore secure interface design by evaluating connection strategies, upstream and downstream dependencies, data sharing between applications, and API design choices like REST or OpenAPI.
Design secure management interfaces using in-band or out-of-band connectivity and standard protocols like ssh, telnet, or rdp, with separate reporting and robust session management.
Explore the differences between in-band and out-of-band management, comparing IP network access via Telnet, SSH, or web portals with lights-out management using serial ports and proprietary networks.
Explore upstream and downstream traffic, plus east–west flows, to secure data-center ingress and egress. Learn how firewalls, proxies, NAT, bastion hosts, and subnetting strengthen network posture against threats.
Explore network protocol design choices and secure protocols, including SSH, tunneling and VPN configurations, with emphasis on firewall placement, encapsulation, authentication, and data encryption.
Explore how ssh provides secure remote access to virtual machines using PuTTY, public and private keys, and port 22, with four steps: connection, key exchange, parameter negotiation, and login.
Compare soap and rest in api design, explaining method-based interfaces, ws security, and xml payloads for soap, versus data-driven, cache-friendly rest with json or xml.
Explore architectural risk assessment by outlining the main steps, identifying defects, and applying the sdlc approach to show how risk drives project success and provide resources.
identify assets, threats, and vulnerabilities within enterprise software architecture; assess risks using the cia triad and develop a risk management plan across the software lifecycle.
Identify and document risks in a risk register, describe each risk, acknowledge stakeholders, assign ownership, probability, severity, action, status, exposure, and priority.
Create and maintain a risk register to document risks with date, vulnerabilities, assign likelihood and impact, and link to supporting documents, while applying project management and change controls.
Develop a risk management plan by assembling a risk register, assigning ownership, and scoring probabilities and impacts. Use a living project management template to guide roles, sponsor, and regular updates.
Clarify six key terms in risk management for section 3.4, distinguish risk management from risk mitigation, and define information assets, risk metrics, flaws, and bugs.
Explore data modeling as a conceptual representation of data objects, covering conceptual, logical, and physical models, and compare ER and UML techniques for database design with keys and constraints.
Classify data by value and sensitivity, assign owners and custodians, and tailor protection schemes. Apply the data lifecycle, risk impact, and CIA triad to ensure availability, integrity, and confidentiality.
Explore common data classifications used in commercial and government sectors, from proprietary and private to confidential, sensitive, secret, and top secret, including unclassified levels.
Explore credential management fundamentals, including storing, managing, and logging user credentials; implement hardware security modules, single sign-on, and federated identities to secure enterprise access.
Master flow control for mitigating ingress and egress traffic across enterprise networks, using bastion hosts, VPNs, v lands, and mac filtering to protect services and hosts.
Identify and classify PCI data, IP, and NPI to prevent data loss using DLP tools. Implement policies, risk assessments, and monitoring across data at rest, in motion, and in use.
Learn to enable Google Cloud Platform data loss prevention, configure detectors and templates, and create regex rules to identify p.i. data such as ssn or credit cards with alerts.
Master operating system controls and the types of controls, including preventive, detective, corrective, deterrent, and application transaction controls, with audit logging and system hardening. Explore defense in depth and resiliency.
Explore what a security design review is and the types of reviews. Discover best practices, the review continuum, and useful checklists and resources.
Design a secure assembly architecture for component-based systems with a focus on storage. Explore data storage and network attached storage to reinforce security in component-based designs.
Explore top security enhancing architecture and design tools, identify various architectures such as Nyst and 0 wasp, and learn which tools and resources are testable on the exam.
Explore security architecture within reference frameworks such as TOGAF, COBIT, ISO, and PCI, and learn how vertical and horizontal controls, trust domains, and SAP integrations shape enterprise security.
Discover design tools and resources for secure deployments, using OWASP cheat sheets, database security guidance, docker security, rest tokens and secrets, and tools like ZAP.
Explore secure design principles and defense in depth, including solid design principles, least privilege, separation of privileges, complete mediation, secrets management, and privacy considerations for building secure software.
Discover secure by design concepts that embed security from the foundation of software architecture, reducing the attack surface with least privilege, defense in depth, and secure defaults.
This lecture offers test tips for secure design, covering asymmetric vs symmetric cryptography, data classification and models, federation and single sign-on versus open authentication, and controls like defense in depth.
Review questions on data models versus data modeling techniques, cloud environments, PKI and public keys for digital certificates, code reuse with SOLID principles, and protection rings in secure software lifecycle.
Please note that the content is broken into TWO Courses. This is Course ONE which is available now on Udemy.
Domain 1-4 is covered in this course....
Content between two courses is over 20 hours.
Earning the globally recognized CSSLP secure software development certification is a proven way to build your career and better incorporate security practices into each phase of the software development lifecycle (SDLC).
CSSLP certification recognizes leading application security skills. It shows employers and peers you have the advanced technical skills and knowledge necessary for authentication, authorization and auditing throughout the SDLC using best practices, policies and procedures established by the cybersecurity experts at (ISC)².
Obtaining your certification will prove your skills, help advance your career, and even gain support from a community of cybersecurity leaders here to help you throughout your professional journey.
The Certified Secure Software Lifecycle Professional (CSSLP) certification is a vendor neutral credential; launched in 2008 by the International Information System Security Certification Consortium, or (ISC)2. This exam is very challenging even to software developers with experience because of the depth of knowledge required to learn in order to pass.
This course has been developed by an industry professional with over twenty years of IT experience. Course contains numerous aids to help the learning process such as demos, discussions, whiteboard designs, test tips, practice reviews and practice questions.
The CSSLP certification validates that the certified professional has the expertise to include the best security practices, auditing, and authorization into each phase of the Software Development Lifecycle (SDLC). SDLC phases include software design, implementation, testing, and deployment.
After earning their CSSLP certification, a software professional will be able to develop a software security program in their organization, reduce production cost, mitigate source code vulnerabilities, and reduce losses because of software breaches.
The CSSLP meets the Level I and II IA System Architecture and Engineering requirements of the DoD mandate 8570.01M. Additionally, the CSSLP certification is accredited for the requirements of ANSI/IEC/ISO Standard-17024.
The CSSLP certification exam is a well written exam evaluating potential candidates across eight different domains. The exam contains 175 question, multiple-choice exam is administered over a 4-hour period at a Pearson Professional Center.
The CSSLP exam questions are developed from the skills and information contained within the CSSLP CBK with the following tested percentages.
Note Course is broken into TWO Courses due to size of content.
Course One Contains content for these Domains (This Course).
Secure Software Concepts – 13%
Secure Software Requirements – 14%
Secure Software Design – 16% Secure Software Implementation/Programming – 16%
Course Two Contains these Domain Objectives.
Secure Software Testing – 14%
Secure Lifecycle Management – 10%
Software Development, Operations, and Maintenance – 9%
Supply Chain and Software Acquisition – 8%
Who would be the target audience?
The audience should be willing to study and review materials to pass the CSSLP Plus and meet the requirements set by ISC2
In order to become a fully certified CSSLP, (ISC)² requires the candidate to have a minimum of four years cumulative paid full-time SDLC experience in one or more of the eight domains of the CSSLP credential. A candidate can substitute one year of experience for a four-year college degree. If a candidate passes the certification exam but does not possess the required years of experience they will become an associate of (ISC)² and have five years to earn the experience. At which time they will become a fully certified CSSLP.
Roles which would benefit from taking the exam.
Software Developers Software Engineers DevOps Engineers Enterprise Architects Application Developers Security Professionals
What you will learn
• Protecting data and business assets and complying with applicable laws and regulations
• Following secure coding standards and how documentation can help in the maintenance and operations of software
• Identifying software vulnerabilities and how to perform testing of units of code
• Managing each phase of the software development life cycle (SDLC)
• Developing security to meet environmental risk and operational challenges
• Supporting incident response, patch and vulnerability management, and continuity of operations
• Supporting the software acquisitions process
• Understanding security related frameworks and best practices
TechCommanders is an online training platform for both aspiring and veteran IT professionals interested in next generation IT Skills.
TechCommanders is led by Joseph Holbrook, a highly sought-after technology industry veteran.
Techcommanders offers blended learning which allows the students to learn on demand but with live training.
Courses offered are used to prepare students to take certification exams in Cloud, DevOps, IT Security and Blockchain.
Techcommanders was established in Jacksonville, Florida in 2020 by Joseph Holbrook, both a US Navy Veteran and a technology industry veteran. Techcommanders, Advancing your NextGen Technology Skills.