CISSP Mastery
All domains
Domain 810% of exam

Software Development Security

5 lessons ~2h

0%
0/5

Building security into software. Integrating security across the SDLC and methodologies (Agile, DevSecOps), securing the development ecosystem and toolchain (CI/CD, SAST/DAST/IAST, repositories), assessing software effectiveness and acquired/third-party software, and applying secure coding standards against source-level weaknesses and API risks.

Exam tips — what to expect

  • 1Source-level flaws and the OWASP Top 10 dominate: recognize SQL injection (fix with parameterized queries + input validation), XSS, buffer overflow, and TOC/TOU race conditions.
  • 2Know the SDLC methodologies and the trap that DevOps = development + QA + operations only (security enters in DevSecOps); be ready for maturity models (SW-CMM, SAMM).
  • 3Database concepts recur: integrity types, keys (a foreign key enforces referential integrity), and the trio of aggregation vs inference vs polyinstantiation.

Lessons

  1. 8.1

    Integrate security in the Software Development Life Cycle (SDLC)

    Know the SDLC phases and how methodologies differ (Waterfall vs Agile vs DevOps/DevSecOps), plus maturity models (CMM, SAMM) that gauge process rigor.

    ~35 min

  2. 8.2

    Identify and apply security controls in development ecosystems

    Secure the toolchain: language/library/tooling choices, IDEs and runtime, CI/CD, configuration management, code repositories, and application security testing (SAST, DAST, SCA, IAST).

    ~40 min

  3. 8.3

    Assess the effectiveness of software security

    Measure whether software controls work via auditing/logging of changes and ongoing risk analysis and mitigation.

    ~20 min

  4. 8.4

    Assess security impact of acquired software

    Evaluate the risk of software you buy or inherit: COTS, open source, third-party, managed services, and cloud (SaaS/IaaS/PaaS).

    ~20 min

  5. 8.5

    Define and apply secure coding guidelines and standards

    Prevent source-level weaknesses (OWASP Top 10, injection, buffer overflow), secure APIs, and adopt secure-coding practices and software-defined security.

    ~30 min

Domain 8 Exam · 50 questions

Complete all 5 lessons above, then take the 50-question exam. Pass at 70% to unlock the next domain.

0/5 lessons done