Software Development Security – Eighth CISSP Objective
Software Development Security makes up 10% of the CISSP exam questions and has five objectives.
- Understanding and integrating security in the software development life cycle, knowledge of development methodologies, maturity models, change management, and DevOps techniques.
- Able to apply security control in software development environments, able to understand security weaknesses or vulnerabilities in the source code level, and securing application programming interface, code repositories in software development environments.
- Able to audit, monitor logs, analyze risks involved and how to mitigate them in software acceptance testing.
- Assessing security impact on software getting from third parties and vendors.
- Define and apply secure coding guidelines and standards in your software development environment.