Domain 1: Secure Software Concepts
- Understand core concepts
- Understand security design principles
Domain 2: Secure Software Lifecycle Management
- Manage security within a software development methodology (e.g., agile, waterfall)
- Identify and adopt security standards (e.g., implementing security frameworks, promoting security awareness)
- Outline strategy and roadmap
- Define and develop security documentation
- Define security metrics (e.g., criticality level, average remediation time, complexity, key performance indicators (KPI), objectives, key results)
- Decommission applications
- Create security reporting mechanisms (e.g., reports, dashboards, feedback loops)
- Incorporate integrated risk management methods
- Implement secure operation practices
Domain 3: Secure Software Requirements
- Define software security requirements
- Identify compliance requirements
- Identify data classification requirements
- Identify privacy requirements
- Define data access provisioning
- Develop misuse and abuse
- Develop security requirement traceability matrix
- Define third-party vendor security requirements
Domain 4: Secure Software Architecture and Design
- Define the security architecture
- Perform secure interface design
- Evaluate and select reusable technologies
- Perform threat modeling
- Perform architectural risk assessment and design reviews
- Model (nonfunctional) security properties and constraints
- Define secure operational architecture (e.g., deployment topology, operational interfaces, continuous integration and continuous delivery (CI/CD))
Domain 5: Secure Software Implementation
- Adhere to relevant secure coding practices (e.g., standards, guidelines, regulations)
- Analyze code for security risks
- Implement security controls (e.g., watchdogs, file integrity monitoring, anti-malware)
- Address the identified security risks (e.g., risk strategy)
- Evaluate and integrate components
- Apply security during the build process
Domain 6: Secure Software Testing
- Develop security testing strategy and plan
- Develop security test cases
- Verify and validate documentation (e.g., installation and setup instructions, error messages, user guides, release notes)
- Identify undocumented functionality
- Analyze security implications of test results (e.g., impact on product management, prioritization, break/build criteria)
- Classify and track security errors
- Secure test data
- Perform verification and validation testing (e.g., independent/internal verification and validation, acceptance test)
Domain 7: Secure Software Deployment, Operations, Maintenance
- Perform operational risk analysis
- Secure configuration and version control
- Release software securely
- Store and manage security data
- Ensure secure installation
- Obtain security approval to operate (e.g., risk acceptance, sign-off at appropriate level)
- Perform information security continuous monitoring
- Execute incident response plan
- Perform patch management (e.g. secure release, testing)
- Perform vulnerability management (e.g., tracking, triaging, common vulnerabilities and exposures (CVE))
- Incorporate runtime protection (e.g., runtime application self protection (RASP), web application firewall (WAF), address space layout randomization (ASLR), dynamic execution prevention)
- Support continuity of operations
- Integrate service level objectives and service level agreements (SLA) (e.g., maintenance, performance, availability, qualified personnel)
Domain 8: Secure Software Supply Chain
- Implement software supply chain risk management (e.g., International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST))
- Analyze third-party software security
- Verify pedigree and provenance
- Ensure and verify supplier security requirements in the acquisition process
- Support contractual requirements (e.g., intellectual property ownership, code escrow, liability, warranty, end-user license agreement (EULA), service level agreement (SLA))