From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,400 courses taught by industry experts.
Post-deployment security testing
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Post-deployment security testing
- [Instructor] Once your deployment is complete, you'll want to ensure that the security tests you performed in pre-production still hold. You should still be performing security testing post-deployment. Scanning for security vulnerabilities can be a complex undertaking so don't assume that it's a one-and-done activity. Once you've deployed your application, you've changed the environment. There's new functionality to consider, new communication pathways, new processes, maybe even new devices. Scanning all of that for vulnerabilities is likely to require multiple scanners with multiple configurations. OWASP is tracking over 60 web application vulnerability scanners on their website, and that isn't even the complete list of scanners that you could choose from. When you scan an application for vulnerabilities, you need to define the configuration for each scan. Will it authenticate to the application or will the scan run without authentication? With it scan the entire application or…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)