Exam Objectives:
The ISC2 CSSLP (Certified Secure Software Lifecycle Professional) exam is designed to test the candidate’s knowledge of secure software lifecycle concepts, principles, and practices. The exam covers eight domains, which include:
- Secure Software Concepts
- Secure Software Requirements
- Secure Software Design
- Secure Software Implementation/Coding
- Secure Software Testing
- Software Acceptance
- Software Deployment, Operations, Maintenance, and Disposal
- Supply Chain and Software Acquisition
Related Books:
The following books can be useful for candidates preparing for the CSSLP exam:
- Certified Secure Software Lifecycle Professional Official Study Guide, Second Edition
- Secure Software Development: A Security Programmer's Guide
- Software Security: Building Security In
- Threat Modeling: Designing for Security
- The Tangled Web: A Guide to Securing Modern Web Applications
Exam Details:
The CSSLP exam consists of 125 multiple-choice and advanced innovative questions, and candidates have four hours to complete it. The passing score for the exam is 700 out of 1000 points. The cost of the exam for ISC2 members is $599, and for non-members, it is $699. The exam is delivered via a computer-based testing (CBT) system, and it is available in English only.
The format of the CSSLP exam is as follows:
- 125 multiple-choice and advanced innovative questions
- 4-hour time limit
- Computer-based testing (CBT)
- Available in English only
To prepare for the exam, candidates can enroll in ISC2’s official CSSLP training course or use study materials, such as the official study guide or other related books. Candidates should also have hands-on experience in secure software development and have a good understanding of software development processes, methodologies, and frameworks.
In conclusion, passing the ISC2 CSSLP exam requires a strong understanding of secure software lifecycle concepts, principles, and practices. Candidates can prepare for the exam by enrolling in the official training course or using study materials such as the official study guide and related books. Hands-on experience in secure software development is also crucial for success on the exam.