Technology Industry
Industry: Email Alert RSS Feed[.sup.2] launch security certification
Database and Network Journal, Oct, 2008
[(ISC).sup.2][R] ("ISC-squared") have announced preparations for a new certification designed to validate secure software development practices and expertise to address the increasing number of application vulnerabilities.
Most RecentTechnology Articles
The Certified Secure Software Lifecycle Professional (CSSLP) aims to stem the proliferation of security vulnerabilities resulting from insufficient development processes by establishing best practices and validating an individual's competency in addressing security issues throughout the software lifecycle (SLC). Code-language neutral, it will be applicable to anyone involved in the SLC, including analysts, developers, software engineers, software architects, project managers, software quality assurance testers and programmers. Over 70 percent of security vulnerabilities exist at the application layer *, presenting a significant, immediate threat to users worldwide. All too often, security is bolted on at the end of the SLC as a response to a threat or after an exposure," said Howard A. Schmidt, CISSP, [(ISC).sup.2] board member and newly appointed president of the Information Security Forum (ISF). A wide range of respected organisations have expressed their support for the CSSLP, including: BASDA, Cisco, ISSA, Frost and Sullivan, Microsoft, SANS, SRA International, Software Assurance Forum for Excellence in Code (SAFEcode), Symantec and Xerox. Several of these organisations are sending their qualified software staff through the education and examination process. Subject areas covered by the CSSLP exam will include the software lifecycle, vulnerabilities, risk, information security fundamentals and compliance. Candidates must demonstrate four years of professional experience in the SLC process or three years of experience and a bachelor's degree (or regional equivalent) in an IT discipline.
The seven domains of the CSSLP CBK[R], a compendium of secure software topics, are:
* Secure Software Concepts
* Secure Software Requirements
* Secure Software Design
* Secure Software Implementation/Coding
* Secure Software Testing
* Software Acceptance
* Software Deployment, Operations, Maintenance and Disposal
Colley added, "The CSSLP ensures that our first line of defense in this war--people--have the tools and knowledge to implement and enforce security throughout the software lifecycle."
The first CSSLP exam is scheduled for the end of June in 2009. Currently, [(ISC).sup.2] is seeking qualified professionals who meet experience and other requirements to participate in the assessment. They will become the first CSSLP holders and be asked to contribute to the exam development process and assist in other program development tasks. Applications for the CSSLP experience assessment will be accepted from Sept. 25, 2008 through March 31, 2009, with the first education seminars slated for Q1 2009. For more information and to register for the experience assessment, visit: www.isc2.org/CSSLP.
>CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Technology Articles
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Speed control of separately excited DC motor
- Building cost comparison between conventional and formwork system: a case study of four-storey school buildings in Malaysia
- Political stability and economic growth in Asia
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market



