ISC2 CISSP - Domain 8 - Software Development Security

Опубликовано: 22 Сентябрь 2026
на канале: Telman Hajibutayev
52
2

💻 Table of Contents
Domain 8: Software Development Security

🏗️ Security in the Software Development Life Cycle (SDLC)
Development Methodologies: Agile, Waterfall, DevOps, DevSecOps, Scaled Agile Framework
Maturity Models: Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM)
Operation and Maintenance
Change Management
Integrated Product Teams

🔐 Security Controls in Development Ecosystems
Programming Languages
Libraries and Tool Sets
Integrated Development Environments (IDE)
Runtime Environments
Continuous Integration & Continuous Delivery (CI/CD)
Software Configuration Management (CM)
Code Repositories
Application Security Testing:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Interactive Application Security Testing (IAST)

📊 Assessing Software Security Effectiveness
Auditing and Logging of Changes
Risk Analysis and Mitigation

🌐 Security Impact of Acquired Software
Commercial-Off-The-Shelf (COTS)
Open Source Solutions
Third-Party Applications
Managed Services (Enterprise Applications)
Cloud Services: SaaS, IaaS, PaaS

🧑‍💻 Secure Coding Guidelines and Standards
Source-Code Level Weaknesses and Vulnerabilities
API Security
Secure Coding Practices
Software-Defined Security