SECURE SOFTWARE DESIGN - C706 EXAM GUIDE
What is the Secure Development Lifecycle? Secure Development Lifecycle. The SDL is the sum of tools, people, models, methodologies, blueprints, metrics that help make systems/software secure. It is focused on baking security into the software/system. What is the TCSDL The trustworthy Computing Security Development Lifecycle was designed by Microsoft and adopted for the development of software needed to withstand attacks. Explain BSIMM. Building Security in Maturity Model is a software security maturity model. BSIMMs cigital and OWASP helps determine where your software security stands at the present time and how to mature it over time. Generates 109 BSIMM activities into 12 practices organized into 4 domains. Which ISO/IEC # standard provides guidance to help organizations embed security within their processes, including application lifecycle processes, that help to secure applications running in the environment. ISO/IEC 27034 Software Development Life Cycle Phases 1.Requirement Gathering and Analysis. 2. Design 3.Implementation and Coding 4. Testing 5. Deployment 6 Maintenance. This individual drives the success of SDL into the SDLC. They typically have 5-10 experience in the field and a vast knowledge of programming/networking/security standards/frameworks with excellent soft skills that can articulate technology/security/business speak well. They touch every aspect of the SDLC & SDL. Drives security architecture. Software Security Architect. Person(s) that manage Software Security Team Software Security Champion (SSC). These individuals have the ability to think like a malicious actor with 3-5 years experience. They understand various software security team tools/plans/processes. They know how to build/deconstruct software. What are the 6 SDL activities/Phases A1 Security Assessment A2 Architecture A3 Design and Development - This maps to Design and Development SDLCA4 Design and Development - this maps to Readiness SDLC A5 Ship _ maps to release and launch SDLC 6 Post-release support PRSA - maps to Support and Sustain What are key activities in the Security Assessment A1 Phase of the SDL? Software team is loped in early. Discovery meeting is initiated. Software security team creates SDL project plan (what further work will be done) Privacy Impact Assessment (PIA)
Document information
- Uploaded on
- September 3, 2023
- Number of pages
- 3
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers