From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,400 courses taught by industry experts.
Common Weakness Enumeration (CWE)
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Common Weakness Enumeration (CWE)
- [Instructor] While the OWASP Top 10 list has gained a significant following, it's not the only resource at your disposal. Another source for helping you find application security vulnerabilities is the Common Weakness Enumeration, or CWE, list from MITRE. In the early 2000s, the MITRE Corporation, a nonprofit focused on security research for US federal agencies, joined forces with US-CERT and the US Department of Homeland Security to build a system to categorize hardware and software vulnerabilities. The system is known as CWE, or Common Weakness Enumeration. In 2010, MITRE teamed up with SANS to identify the top 25 most dangerous software errors, using MITRE's CWE as the foundation for that activity. By combining their research, they were able to create a more detailed, more robust list than the OWASP Top 10, providing security testers with even deeper insights into application security risks they should consider. The list remained static from 2011 until 2019, when it received its…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)