Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 10 páginas
Examen

D487 Study Question with 100% Verified Answers

Document preview thumbnail
Vista previa 2 fuera de 10 páginas

D487 Study Question with 100% Verified Answers

Vista previa del contenido

D487 Study Question with 100% Verified
Answers
Building Security In Maturity Model (BSIMM)

A study of real-world software security initiatives organized so that you can determine where

you stand with your software security initiative and how to evolve your efforts over time

SAMM

offers a roadmap and a well-defined maturity model for secure software development and

deployment, along with useful tools for self-assessment and planning.

Core OpenSAMM activities

Governance

Construction

Verification

Deployment

static analysis

Source code of an application is reviewed manually or with automatic tools without running

the code

dynamic analysis

Analysis and testing of a program occurs while it is being executed or run

Fuzzing

Injection of randomized data into a software program in an attempt to find system failures,

memory leaks, error handling issues, and improper input validation

OWASP ZAP

, -Open-source web application security scanner

-Can be used as a proxy to manipulate traffic running through it (even https)

ISO/IEC 27001

Specifies requirements for establishing, implementing, operating, monitoring, reviewing,

maintaining and improving a documented information security management system

ISO/IEC 17799

ISO/EIC is a joint committee that develops and maintains standards in the IT industry. is an

international code of practice for information security management. This section defines

confidentiality, integrity and availability controls.

ISO/IEC 27034

A standard that provides guidance to help organizations embed security within their processes

that help secure applications running in the environment, including application lifecycle

processes

Software security champion

a developer with an interest in security who helps amplify the security message at the

team level

waterfall methodology

a sequential, activity-based process in which each phase in the SDLC is performed

sequentially from planning through implementation and maintenance

Agile Development

A software development methodology that delivers functionality in rapid iterations, measured

in weeks, requiring frequent communication, development, testing, and delivery.

Información del documento

Subido en
15 de agosto de 2026
Número de páginas
10
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$11.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
KenAli
2.6
(18)
Vendido
103
Seguidores
5
Artículos
21938
Última venta
5 días hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes