Phase 4B · ISC2 CSSLP

Certified Secure Software Lifecycle Professional

Chứng chỉ CSSLP dành cho developer và security engineer: tích hợp bảo mật vào mọi giai đoạn phát triển phần mềm — từ thiết kế, code, kiểm thử đến vận hành và chuỗi cung ứng. (Security embedded into every phase of the SDLC.)

Danh sách chương — Chapter list

8
Chương học
16
Bài Lab thực hành
125
Câu hỏi kiểm tra
ISC2
Tổ chức cấp chứng chỉ
01
D1 · 10%

Khái niệm SDLC an toàn

Secure Software Concepts — SDLC models, trust boundaries, threat modeling, STRIDE, privacy by design.

02
D2 · 14%

Yêu cầu bảo mật phần mềm

Secure Software Requirements — misuse cases, RTM, GDPR/HIPAA/PCI-DSS requirements, security user stories.

03
D3 · 14%

Thiết kế phần mềm an toàn

Secure Software Design — design patterns, API security, cryptography, microservices mTLS, mobile security.

04
D4 · 14%

Triển khai an toàn

Secure Software Implementation — CERT standards, injection prevention, memory security, secrets management.

05
D5 · 14%

Kiểm thử bảo mật

Secure Software Testing — SAST/DAST/IAST/SCA, ZAP, Burp Suite, fuzz testing, OWASP Testing Guide.

06
D6 · 11%

Quản lý vòng đời

Secure Lifecycle Management — DevSecOps, CI/CD security gates, OWASP SAMM, vulnerability management.

07
D7 · 11%

Triển khai & Vận hành

Software Deployment, Operations & Maintenance — RASP, container runtime security, secrets rotation, APM security.

08
D8 · 12%

Chuỗi cung ứng phần mềm

Supply Chain & Software Acquisition — SLSA, SBOM, SPDX/CycloneDX, Sigstore, NIST SSDF, OSS security.

Phase 4A: CCSP Phase 4C: CGRC
Zalo