Ready to ace the CISSP exam? Join our study group and get the ultimate guide to the Certified Information Systems Security Professional (CISSP) certification!
Session 29 completes Domain 8: Software Development Security. We will cover the following exam objectives:
8.3 Assess the effectiveness of software security
8.4 Assess security impact of acquired software
8.5 Define and apply secure coding guidelines and standards
Access slides, practice questions, and more: https://cissp.brittwhite.io
A huge thank you to Rotas Security for supporting this study group. Check them out at https://rotassecurity.com/ for your offensive security needs.
CISSP Resource Links:
Exam Outline: https://www.isc2.org/certifications/c...
Chapters:
00:00 Intro to CISSP Study Group
00:47 Today's Outline
01:23 Why Software Security Matters
02:32 Objective 8.3: Assessing Software Security
04:07 Main Testing Approaches
05:09 DevSecOps Integration
05:47 Objective 8.4: Acquired Software Security
06:35 Commercial Off The Shelf Software (COTS) Assessment
07:16 Open Source Software Assessment
07:49 Third Party Software Assessment
08:13 Managed Services Assessment
08:50 Objective 8.5: Secure Coding Guidelines
09:59 Common Security Vulnerabilities
11:22 API Security Essentials
12:57 Secure Coding Best Practices
15:46 Preventing Development Vulnerabilities
16:26 Advanced Software Security Concepts
17:42 Software Defined Security
18:46 Key Takeaways
20:03 Conclusion & Next Steps