From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Storing and managing security data
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Storing and managing security data
- [Presenter] In addition to the source code, your release process should account for the security data that your application needs to function. And what do I mean by security data? This includes things like credentials, secrets, keys, certificates, and configurations. Back in the very first domain, Secure Software Concepts, we discussed identity and access management, or IAM. As your application moves through its lifecycle from design to development and eventually to deployment, you can start to see how these concepts are applied at each stage. This is a great example. When you deploy your application and the ops team takes control, that team needs access to security data in order to administer and manage the application. End users also need to log in, and trusted applications need the ability to authenticate to and interact with your application. As a CSSLP, it's your responsibility to make sure that data is accessible to the right people and to trusted integrations, but not…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)