Certified Secure Software Lifecycle Professional (CSSLP)

Price
Net
VAT

Price
Price on Request

Duration
5 days

For companies and job seekers:
this course is 100% fundable!
 

Location

Course Language
English

Training Solutions
Online Live

Secure software is not created at the end, but throughout the entire development process. Modern development models, cloud architectures, and AI-supported systems significantly increase security requirements.

Key topics

  • Secure Software Development Lifecycle (SSDLC)
  • Security by Design and Threat Modeling
  • Secure architecture, APIs, and cloud environments
  • DevSecOps, automation, and AI-supported testing
  • Risk Management, Compliance, and Governance
  • Vulnerability analysis and secure supply chains

Prerequisites
Basic understanding of software development, IT architectures, or IT security.

Target audience
Software developers, security managers, architects, DevOps roles, and IT management and quality assurance professionals.

Sustainable software security is becoming a strategic success factor. A structured view of processes, technologies, and responsibilities strengthens quality, resilience, and trust in digital products.

Print as PDF
Course content
  • Core concepts
  • Principles for security design
  • Definition of software security requirements.
  • Identification and analysis of compliance requirements.
  • Identification and analysis of data classification requirements.
  • Identification and analysis of data protection requirements.
  • Development of misuse and abuse cases.
  • Development of a security requirements traceability matrix (STRM).
  • Ensuring that security requirements are communicated to suppliers/providers.
  • Performing threat modeling.
  • Defining the security architecture.
  • Implementation of a secure interface design.
  • Performing an architectural risk assessment.
  • Modeling (non-functional) security properties and constraints.
  • Modeling and classification of data.
  • Evaluation and selection of reusable secure designs.
  • Performing a security architecture and design review.
  • Define secure operating architecture.
  • Use secure architecture and design principles, patterns, and tools.
  • Compliance with relevant practices for secure programming.
  • Analyzing code for security risks.
  • Implementation of security controls.
  • Handling security risks.
  • Secure reuse of third-party code or libraries.
  • Secure integration of components.
  • Application of security measures during the build process.
  • Development of security test cases.
  • Development of a strategy and plan for security testing
  • Review and validation of documentation.
  • Identification of undocumented functions.
  • Analysis of the safety implications of test results.
  • Classification and tracking of security bugs.
  • Secure test data
  • Performing verification and validation tests.
  • Secure configuration and version control.
  • Define strategy and roadmap.
  • Manage security within a software development methodology.
  • Identify security standards and frameworks.
  • Define and develop security documentation.
  • Develop security metrics.
  • Decommission software.
  • Report security status.
  • Integrate integrated risk management (IRM).
  • Promote a security culture in software development. Implement continuous improvement.

Frequently asked questions

  • CSSLP is an internationally recognized certification for secure software development. The focus is on security throughout the entire software lifecycle.
  • Suitable for professionals in software development, IT security, architecture, DevOps, and quality assurance with a focus on secure applications.
  • The course covers security requirements, design, development, testing, deployment, maintenance, risk management, and compliance in software projects.
  • CSSLP strengthens expertise in secure software development, increases professional recognition, and improves opportunities in security-critical IT roles.
  • Several years of professional experience in the software development process are required. Alternatively, experience can be supplemented by training or other certifications.
  • CSSLP focuses specifically on application security in the development process and not on general IT or network security.
  • Increasing cyberattacks, cloud applications, and legal requirements make security in the software lifecycle a key success factor.

Do you have any further questions? Please contact us.