All 25 CISSP Domain 8 objectives — Software Development Security — complete, in 17 minutes. Every leaf of the ISC2 2024 exam outline, one idea at a time.
This is the whole of CISSP Domain 8, Software Development Security, in one sitting. It is 10% of the exam. The domain covers building security into the development lifecycle, and judging the software you did not write.
Every chapter below is one leaf of the ISC2 2024 exam outline, explained in about half a minute with an animated diagram. Jump straight to an objective you are weak on, or let the whole domain run as a review before a practice exam.
Who it is for: candidates working the 2024 outline domain by domain, and practitioners who want a fast, accurate refresher without sitting through a full course.
Covered in this video: Development Methodologies, Maturity Models, Operation and Maintenance, Change Management in the SDLC, Integrated Product Team, Programming Languages, Libraries and Dependencies, Tool Sets, and 17 more.
Chapters:
0:00 Domain 8: Software Development Security
0:18 Understand and integrate security in the Software Development Life Cycle
0:29 Development Methodologies
1:02 Maturity Models
1:36 Operation and Maintenance
2:10 Change Management in the SDLC
2:46 Integrated Product Team
3:19 Identify and apply security controls in software development ecosystems
3:29 Programming Languages
4:11 Libraries and Dependencies
4:45 Tool Sets
5:20 Integrated Development Environment
5:59 Runtime
6:36 Continuous Integration and Continuous Delivery
7:10 Software Configuration Management
7:49 Code Repositories
8:21 Application Security Testing — SAST, DAST, SCA and IAST
9:02 Assess the effectiveness of software security
9:13 Auditing and Logging of Changes
9:50 Risk Analysis and Mitigation
10:26 Assess security impact of acquired software
10:36 Commercial Off-the-Shelf Software
11:13 Open Source Software
11:51 Third-Party Software and Supply Chain
12:34 Managed Services
13:05 Cloud Services — SaaS, PaaS and IaaS
13:43 Define and apply secure coding guidelines and standards
14:23 Source-Code Weaknesses and Vulnerabilities
15:00 API Security
15:39 Secure Coding Practices
16:15 Software-Defined Security
Study guide, practice exam and revision sheets for this domain: https://learn.securepathdigital.net/
▶ Subscribe: / @securepathdigital
Secure Path Digital — CISSP micro-lessons and full domain reviews, built objective by objective from the ISC2 2024 exam outline.
#CISSP #CISSPDomain8 #SecureCoding #DevSecOps #ISC2
Part of the Secure Path Digital CISSP path — a micro-lesson for every objective in the ISC2 2024 exam outline, one idea at a time.
The rest of the path: Domain 1 Security and Risk Management · Domain 2 Asset Security · Domain 3 Security Architecture and Engineering · Domain 4 Communication and Network Security · Domain 5 Identity and Access Management (IAM) · Domain 6 Security Assessment and Testing · Domain 7 Security Operations.