💻 Table of Contents
Domain 8: Software Development Security
🏗️ Security in the Software Development Life Cycle (SDLC)
Development Methodologies: Agile, Waterfall, DevOps, DevSecOps, Scaled Agile Framework
Maturity Models: Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM)
Operation and Maintenance
Change Management
Integrated Product Teams
🔐 Security Controls in Development Ecosystems
Programming Languages
Libraries and Tool Sets
Integrated Development Environments (IDE)
Runtime Environments
Continuous Integration & Continuous Delivery (CI/CD)
Software Configuration Management (CM)
Code Repositories
Application Security Testing:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Interactive Application Security Testing (IAST)
📊 Assessing Software Security Effectiveness
Auditing and Logging of Changes
Risk Analysis and Mitigation
🌐 Security Impact of Acquired Software
Commercial-Off-The-Shelf (COTS)
Open Source Solutions
Third-Party Applications
Managed Services (Enterprise Applications)
Cloud Services: SaaS, IaaS, PaaS
🧑💻 Secure Coding Guidelines and Standards
Source-Code Level Weaknesses and Vulnerabilities
API Security
Secure Coding Practices
Software-Defined Security