CSSLP: Certification Exam preparation
Description:
CSSLP (Certified Secure Software Lifecycle Professional) is an international professional certification and commercially independent in systems safety. The certification program is managed by the consortium "International Information Systems Security Certification" (ISC �).
Target audience:
This training aims to prepare learners for the certification exam CSSLP. This course enables learners to acquire knowledge and all matters related to giving them the skills to carry with success the certification exam.
Learning Objectives:
- 1. Learn to develop software by integrating security features as soon as possible.
- 2. Recognize the aspects to consider when developing and deploying secure software.
- 3. Being able to design, develop and deploy secure software.
- 4. Know the ten best practices recognized by the industry to develop secure software.
- 5. Being able to correctly understand the exam questions.
Duration: 5 days
Course content:
- MODULE 1
- Secure software concepts
- MODULE 2
Requirements for secure software
- - Partners participation
- - Identification of the regulatory framework, legal and regulatory and compliance of IT requirements.
- - Identification of issues in terms of the triad: Availability, Integrity, Privacy
- - Identification of requirements in supply
- - Risk Assessment
- MODULE 3
Secure software concepts
- - Modeling case
- - Revision of core security concepts
- - Revision of the security architecture
- - Modeling risks and threats
- - Security requirements definition
- - Test security scenarios definition
- MODULE 4
Implementation of security software / codes
- - Secure code writing
- - Source code revision
- - Preparation of documentation of security features
- MODULE 5
Design security tests
- - Security tests
- - Assessment of residual risks
- MODULE 6
Software
acceptance
- MODULE 7
Software deployment, maintenance, operation, removal
- - Secure Installation
- - Vulnerability Assessment
- - Penetration testing
- - Obtaining the certification and security accreditation
- - Residual risk management
- - Change management
- - Control panel
- - Certification obtention and security accreditation
- - Incident management
- - Audit
- - Monitoring and continuous improvement
- - Secure archiving
- - Secure magnetic standard erasal
- - Safe removal
- - Lessons Learned
- MODULE 8
Revision