From the course: Certified Secure Software Lifecycle Professional (CSSLP) Exam Tips

Unlock the full course today

Join today to access over 22,700 courses taught by industry experts or purchase this course individually.

Secure Software Supply Chain

Secure Software Supply Chain

From the course: Certified Secure Software Lifecycle Professional (CSSLP) Exam Tips

Start my 1-month free trial

Secure Software Supply Chain

- [Instructor] The eighth domain of the CSSLP is secure software supply chain. This domain focuses on how you can extend your software security expectations to your third-party suppliers. Secure software supply chain accounts for 11% of the CSSLP exam. The primary focus of this domain is on implementing software supply chain risk management processes. You'll learn about this by studying how you can identify, assess, respond to and monitor those risks. You'll learn techniques for analyzing the security of third-party software, which will lead to a discussion on verifying the pedigree and provenance of that software. While pedigree and provenance are related concepts you'll dig deep into what makes each one unique. You'll study concepts including interdiction mitigation, code repository security, and cryptographically hashed, digitally signed components. Ensuring supplier security requirements in the acquisition process…

Contents