Koulutus
Overview
The Official ISC2 training course for the Certified Secure Software Lifecycle Professional (CSSLP) provides a comprehensive and structured review of the knowledge required to integrate security practices such as authentication, authorisation, and auditing into every phase of the Software Development Lifecycle. The course covers secure design, development, testing, deployment, and supply chain considerations to ensure resilient and secure software systems. Delivered as a five-day virtual instructor-led training course, this programme aligns fully with the ISC2 Common Body of Knowledge and prepares learners to confidently approach the CSSLP certification. The course combines expert-led instruction, official ISC2 courseware and exam voucher, and interactive learning elements to reinforce secure software development principles.
Prerequisites
- Minimum of four years cumulative paid SDLC work experience in one or more CSSLP domains
- Alternatively, three years of SDLC experience with a relevant degree in computer science, IT, or related field
Target audience
This course is designed for professionals with experience in software development lifecycle practices. It is particularly suitable for:
- Software developers
- Engineers and architects
- Product managers
- Project managers
- Software QA professionals
- QA testers
- Business analysts
- Professionals managing software development stakeholders
Objectives
By the end of this course, learners will be able to:
- Apply core software security principles to development processes
- Integrate security controls across all SDLC phases
- Analyse and define secure software requirements
- Design secure architectures and perform threat modelling
- Implement secure coding practices and mitigate vulnerabilities
- Conduct security testing and validation
- Manage secure deployment, operations, and maintenance
- Evaluate and mitigate software supply chain risks
Outline
Module 1: Secure software concepts
- Understand core security objectives and principles
- Apply confidentiality, integrity, and availability concepts
- Explore authentication, authorisation, and auditing
- Understand secure design principles and practices
Module 2: Secure software requirements
- Identify and analyse security requirements
- Apply compliance and regulatory considerations
- Develop misuse and abuse cases
- Implement requirements traceability
Module 3: Secure software architecture and design
- Perform threat modelling and risk assessment
- Design secure architectures and patterns
- Evaluate attack surfaces and security controls
- Apply authentication and authorisation mechanisms
Module 4: Secure software implementation
- Apply secure coding standards and practices
- Identify and mitigate common vulnerabilities
- Implement cryptographic controls
- Manage third-party components and dependencies
Module 5: Secure software testing
- Develop and execute security testing strategies
- Perform vulnerability scanning and penetration testing
- Apply static and dynamic testing methods
- Analyse and prioritise security defects
Module 6: Secure software lifecycle management
- Integrate security into SDLC methodologies
- Apply DevOps and DevSecOps practices
- Implement risk management and governance
- Monitor and improve software security processes
Module 7: Secure software deployment, operations and maintenance
- Implement secure deployment and configuration
- Manage secrets, keys, and certificates
- Apply monitoring, logging, and incident response
- Maintain secure systems through patching and updates
Module 8: Secure software supply chain
- Identify and manage supply chain risks
- Secure third-party and open-source components
- Apply vendor and contract security requirements
- Ensure integrity of software components and distribution
Hands-on learning
This course emphasises practical application through immersive, scenario-based learning aligned to real-world software development environments.
- Applied scenarios demonstrating secure SDLC practices
- Practical exercises across all eight CSSLP domains
- Case studies exploring real-world software security challenges
- Instructor-led walkthroughs of secure design and coding practices
- Peer discussions to explore different approaches to software security
This hands-on approach ensures learners can apply secure development principles effectively within their own organisations.
Exams and assessments
This course includes the official exam voucher, comprehensive range of assessments designed to reinforce learning and prepare learners for the CSSLP certification exam.
- Official ISC2 CSSLP exam aligned to eight domains of the Common Body of Knowledge
- Exam duration of three hours
- Total of 125 multiple-choice questions
- Passing score set at 70 percent
Learners will leave the course with a clear understanding of their strengths and areas for further study, ensuring a focused and effective approach to certification.
What's included
- Expert instruction delivered by an authorised official ISC2 instructor
- Official ISC2 student training guide
- Chapter quizzes to reinforce knowledge retention
- Applied scenarios with corresponding SDLC activities
- Peer discussions on key software security topics
- Practical activities including six case studies
- End-of-chapter quizzes with detailed explanations
Osta liput
QA’s online-courses from Tieturi
Questions about QA courses?
Find out how QA’s live online courses work, what you need to participate, and what to expect before booking your training.