Domain 8 · 10% of the exam
Software Development Security
Security professionals must understand the principles of software development security and the different tools and techniques that can be used to incorporate security into the SDLC. This includes understanding secure coding practices, code reviews and testing, and incorporating security into the design, deployment, and maintenance of software.
Learning objectives
- Explain the value and use of secure coding standards, guidelines, frameworks, and architectural concepts. I
- Differentiate between major secure coding and management methodologies to support selection of organizational software development practices.
- Explain the security implications of managing software development, deployment, and support, including: Security advantages of mature programming environments and tool sets, risks and benefits of code repositories and libraries, value of integrated development environments (IDEs).
- Contrast legacy software configuration management (CM) approaches with automated configuration tools.
- Identify approaches for appropriate security testing in systems development environments.
- Identify methods and artifacts that would support security assessment of thirdparty vendors, COTS and commodity systems, and orphaned systems elements.
- Explain the software security assessment issues that arise during organizational mergers and acquisitions.
- Identify and understand major causes of security issues in source code, database and data warehouse systems, and web environments.
Key topics
- Assess Effectiveness
- SDLC
- Secure Guidelines and Standards
- Security Impact of Acquired Software
- Software Security Controls
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01Software Defined SecuritySoftware-defined security (SDS) is a major paradigm shift in the ways in which we need to think about information systems architectures and keeping them secure.17 slides · 9 min read
- 02Designing and Writing Software - Source vs. Executable CodeПIO 1010 10100011001 0101100000 1010 000 JOl110110 10H100000100g6 slides · 2 min read
- 03Common Object Request Broker Architecture (CORBA)Common Object Request Broker Architecture (CORBA) is a set of standards that addresses the need for interoperability between hardware and software products residing on different machines across a network.5 slides · 2 min read
- 04Malformed Input AttacksA number of attacks that use input from the user and somehow inject or modify such input currently exist and are known.2 slides · 1 min read
- 05Programming Language SupportDifferent programming languages and their associated development tools can make or break an organization's efforts to bake in security from the start of development.2 slides · 1 min read
- 06Race Conditions vs. Time of Check vs. Time of Use (TOCTOU) AttacksRace Conditions vs. Time of Check vs. Time of Use (TOCTOU) Attacks8 slides · 4 min read
- 07Object-Oriented SecurityIn object-oriented systems, objects are encapsulated. Encapsulation protects the object by denying direct access to view or interact with what is located inside the object, this is referred to as data hiding.6 slides · 2 min read
- 08Orphaned Software and Systems Security AssessmentOrganizations sometimes are stuck with system elements that are no longer supported by their original manufacturer or vendor, and for which no effective thirdparty software or firmware support is available.2 slides · 1 min read
- 09Object-Oriented Technology and ProgrammingX": True False False False True False ROR_Z"s False False True nd -add Most object-oriented languages have the following key characteristics. ts.activi modifier cted_ob lame]. se int ("please select exactl To OPERATOR CLASSES ---3 slides · 2 min read
- 10Risk vs. Business NeedSimply put, business needs are all the processes and activities required to both run a business and make it profitable.7 slides · 2 min read
- 11Auditing and Logging of ChangesChange management and control must first decide at what level of granularity will the elements of the system be defined, enumerated, managed, and controlled.6 slides · 2 min read
- 12Process to Identify Business NeedsComparing risk to business needs ensures that security measures align with organizational priorities, balancing protection efforts against operational goals and acceptable risk levels.5 slides · 2 min read
- 13Waterfall ModelThe Waterfall model is a sequential (noniterative) approach used in software development processes (see figure below). In this model, progress towards software project completion flows steadily downwards (like a waterfall) through various phases of the…4 slides · 1 min read
- 14Project Initiation and PlanningIncluding security requirements in project initiative and planning ensures that timelines, budgets, and deliverables account for security at every phase.4 slides · 1 min read
- 15Certification and AccreditationCertification and accreditation is sometimes referred to as "Security Authorization."4 slides · 2 min read
- 16Advanced Persistent Threat and Insider Threat0M05549 CT10009887655069980264 slides · 1 min read
- 17Managed Services and Security AssessmentNot surprisingly, most organizations also exist within some other organizations' supply chain. The principles of supply chain management must be applied to both upstream (supplier) and downstream (customer) relationships.4 slides · 1 min read
- 18Security Assurance for Commercial Off-the-Shelf SystemsWhen managing security risks, in an organization's technology environment, it is essential to understand the nature and limitations of commercially acquired software products.2 slides · 1 min read
- 19REST API Authentication OptionsThere are three typical options available when addressing authentication protocols with regard to REST APls.5 slides · 2 min read
- 20Software Assurance During Acquisition - A Phased ApproachFour basic phases of activity shape the ways in which organizations acquire software systems via thirdparty systems providers, integrators, or consultants.8 slides · 4 min read
- 21Covert ChannelsA covert channel may be defined as a communication channel that allows processes to transfer information in such a way to violate some security policy or requirement.5 slides · 3 min read
- 22Time of Check vs. Time of Use (TOCTOU) AttacksTime of Check vs. Time of Use (sometimes written as TOCTOU or TOC/TOU) is seemingly a very common type of attack that occurs when control information changes between the time the system security functions check the contents of variables and the time the…2 slides · 1 min read
- 23Software Project Life Cycle MethodsSoftware development methodologies provide structured approaches for planning, building, testing, and delivering software, ensuring quality, efficiency, and alignment with requirements.3 slides · 1 min read
- 24Functional Requirements DefinitionDefining functional requirements with embedded security considerations directs development toward applications that satisfy user needs while meeting protection goals.5 slides · 2 min read
- 25Software Assurance and Security AssessmentApplication software has become an integral component in every organization over the last number of decades, and building better applications that have the proper security controls built-in based on requirements becomes very important.4 slides · 1 min read
- 26Cross-Disciplinary MethodsIntegrated product and process development is a management approach that uses integrated product teams to optimize all aspects of product development, from design to support.5 slides · 3 min read
- 27Common Exploitable Software Source Code ErrorsCommon exploitable source code errors often arise from poor input validation, insecure coding practices, and inadequate error handling during development.3 slides · 1 min read
- 28Case Study - British AirwaysCase studyOn October 16, 2020, Elizabeth Denham, a commissioner for the Information Commissioner's Office (ICO) concluded the following of British Airways (BA): "People entrusted their personal details to BA and BA failed to take adequate measures to keep those…4 slides · 2 min read
- 29Toolsets, Libraries, Repositories, and Integrated Development Environments (IDEs) - Integrated Development Environments (IDEs)Toolsets, Libraries, Repositories, and Integrated Development Environments (IDES): Integrated Development Environments (IDEs)2 slides · 1 min read
- 30Toolsets, Libraries, Repositories, and Integrated Development Environments (IDEs) - Programming Tools and ToolsetsToolsets, Libraries, Repositories, and Integrated Development Environments (IDEs): Programming Tools and Toolsets4 slides · 1 min read
- 31Programming Language GenerationsFor the first 30 or 40 years of the computer age, it was common to categorize programming languages into loosely defined generations.7 slides · 3 min read
- 32Between-the-Lines, Trapdoor - Backdoor, and Social Engineering AttacksBetween-the-Lines, Trapdoor/Backdoor and Social Engineering Attacks3 slides · 2 min read
- 33Dynamic and Static AnalysisDynamic Analysis6 slides · 3 min read
- 34Acceptance TestingAcceptance testing is a formal test conducted to determine whether the system satisfies its acceptance criteria and to enable the owner/customer to determine whether to accept the system.3 slides · 1 min read
- 35Regression Testing, Security Assessment Testing, and Testing and Evaluation of ControlsRegression Testing, Security Assessment Testing, and Testing and Evaluation of Controls6 slides · 3 min read
- 36PolyinstantiationPolyinstantiation is a mechanism that helps in controlling access and preventing unauthorized data exposure.2 slides · 1 min read
- 37Development and ImplementationContinuing with the development and implementation phase, other types of controls that would need to be coded into the system and applications would be related to data validation, logging and monitoring, version control, etc.3 slides · 1 min read
- 38Security of Code RepositoriesRestricting access to code repositories, verifying changes, monitoring activity, and maintaining version integrity help safeguard source code from theft or tampering.3 slides · 1 min read
- 39Procedural Versus Object-Oriented ConceptsProcedural programming is action-focused, while object-oriented programming is organized around objects and their interactions.5 slides · 3 min read
- 40Standard Libraries, Other Libraries, and Software ReuseReviewing both standard and external libraries before reuse helps prevent introducing vulnerabilities and ensures alignment with organizational trust requirements. VER (2.6.3), 57311.B3 275 slides · 3 min read
- 41IDEs, Program Execution, and the Runtime EnvironmentSecuring the integrated development environment (IDE), the program execution process, and the runtime environment collectively contributes to building a resilient runtime environment. AMC4 slides · 1 min read
- 42Designing and Writing Software - OverviewOrganizations or individuals use some version of a software development process to take their ideas about a task that must be performed and turn that into a set of instructions and data that a computer or a set of computers) can execute. not None ext):…4 slides · 2 min read
- 43Security of Application Programming InterfacesProtecting application programming interfaces with authentication, encryption, access controls, and validation reduces the risk of unauthorized data access or service misuse.2 slides · 2 min read
- 44Memory or Other Object ReuseControlling memory reuse and object reuse prevents leftover data exposure and reduces the risk of unauthorized access or tampering.2 slides · 2 min read
- 45Case Study - Equifax and Apache StrutsCase studyDeveloped in May 2000 by Craig McClanahan, Apache Struts 1 is an opensource framework. It was designed to extend the Java applications program interface (API) to provide a mechanism that allowed developers to use a model-viewcontroller (MVC) architecture.3 slides · 2 min read
- 46Possible Responses (Case Study - Equifax and Apache Struts)Case study answersPatching the vulnerability was too complicated and labor-intensive. Given that websites may have depended on hundreds of applications that relied on Struts, patching this vulnerability was a complicated and labor-intensive process. Applications would have…1 slides · 1 min read
- 47Controls for Incomplete Parameter Checking and EnforcementMeasures are put in place to address and prevent the security vulnerability of incomplete or absent validation of user-supplied input (parameters).2 slides · 2 min read
- 48Open-Source Software and Security AssessmentOpen-source application software is source code that is made generally available to anyone.2 slides · 2 min read
- 49REST-based API Security RecommendationsA 000O3 slides · 1 min read
- 50OWASP Top 10 Web Application Security RisksThe OWASP Top 10 is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to web applications.3 slides · 1 min read
- 51Software Acquisition via Third-Party DevelopmentManaging third-party software acquisition carefully ensures purchased products meet security requirements, avoid hidden vulnerabilities, and remain free or malicious code.2 slides · 1 min read
- 52OWASP Maturity ModelsOWASP has developed the Software Assurance Maturity Model (SAMM) that focuses on the use of CMM processes and thinking to achieve greater quality, stability, and security for software systems.3 slides · 1 min read
- 53Customer Acceptance and Independent EvaluationCustomer acceptance and independent evaluations confirm that systems meet contractual requirements, align with operational needs, and resolve issues before full deployment.7 slides · 3 min read
- 54Formal Assessment of Nonfunctional Requirements and Software Assurance PolicyEvaluating nonfunctional requirements alongside assurance policies confirms that performance, compliance, and reliability align with security objectives.4 slides · 3 min read
- 55Secure Coding Guidelines and StandardsAdhering to secure coding guidelines and standards reduces vulnerabilities, improves code maintainability, and increases resilience to emerging threats.3 slides · 3 min read
- 56Trusted Libraries and Secure Programming Standards and GuidelinesRelying on trusted libraries while following secure programming standards and guidelines strengthens code integrity and improves long-term security posture. PIA SERVER (2.6.32, 573.11.B5 178 MUL-2.8-312-573.1.1.EL6.K062 10% KU KULL4 slides · 1 min read
- 57Vulnerabilities Across the Cycle of Software Build and UseUnderstanding vulnerabilities across the entire software life cycle, from design to decommissioning, helps prevent exploitation and improve resilience over time.2 slides · 1 min read
- 58Operations and MaintenanceOperations and maintenance encompasses the activities required for the day-to-day operation of assets and systems, as well as the efforts to maintain, repair, and optimize them to ensure functionality, efficiency, and safety throughout their lifespan.4 slides · 1 min read
- 59Secure Software and Systems Needs for Configuration ManagementApplying strong configuration management practices protects software integrity, prevents unauthorized modifications, and maintains stable deployment environments. NO M OMO2 slides · 1 min read
- 60Testing, Verification, and Security AssessmentTesting is the process of using a system (or some of its components) in a scripted, controlled way to see if a specified set of inputs and initial conditions produce the required results.2 slides · 1 min read
- 61Control Data-Centric VulnerabilitiesImplementing rigorous validation and secure data handling procedures reduces the risk of leaks, breaches, and manipulation of sensitive information.2 slides · 1 min read
- 62Software Development MethodologiesA software development methodology is the collection of managed activities that can be used to translate end users' needs for function and capability into a software system that meets those needs.15 slides · 7 min read
- 63Make Software Secure by Design, Build, and DevelopmentApplying secure design principles in planning, building, developing, and maintaining software embeds protection into every stage of the product life cycle.3 slides · 1 min read
- 64Who Writes Your Source CodeAnother way to ask this question might be, "How do you assure the security and integrity of your software logistics and supply chain?"4 slides · 2 min read
