Danh sách chương — Chapter list
Khái niệm SDLC an toàn
Secure Software Concepts — SDLC models, trust boundaries, threat modeling, STRIDE, privacy by design.
Yêu cầu bảo mật phần mềm
Secure Software Requirements — misuse cases, RTM, GDPR/HIPAA/PCI-DSS requirements, security user stories.
Thiết kế phần mềm an toàn
Secure Software Design — design patterns, API security, cryptography, microservices mTLS, mobile security.
Triển khai an toàn
Secure Software Implementation — CERT standards, injection prevention, memory security, secrets management.
Kiểm thử bảo mật
Secure Software Testing — SAST/DAST/IAST/SCA, ZAP, Burp Suite, fuzz testing, OWASP Testing Guide.
Quản lý vòng đời
Secure Lifecycle Management — DevSecOps, CI/CD security gates, OWASP SAMM, vulnerability management.
Triển khai & Vận hành
Software Deployment, Operations & Maintenance — RASP, container runtime security, secrets rotation, APM security.
Chuỗi cung ứng phần mềm
Supply Chain & Software Acquisition — SLSA, SBOM, SPDX/CycloneDX, Sigstore, NIST SSDF, OSS security.