InfoSec Bites

CISSP Domain-8: Software Development Security


Listen Later

The dicussion in this podcast offers a comprehensive overview of Software Development Security, covering the Software Development Life Cycle (SDLC) and various Development Methodologies. The text systematically explains the phases of the SDLC—including requirements gathering, design, development, testing, and operations and maintenance—while stressing the importance of integrating security at every stage. Furthermore, the discussion contrasts traditional methods like Waterfall with iterative approaches such as Agile, Spiral, and Rapid Application Development (RAD), and introduces modern team structures like DevOps and DevSecOps. Finally, it details the technical aspects of software development, including programming language generations, Object-Oriented Programming (OOP) concepts, application security testing (SAST, DAST, Fuzzing), and methods for assessing the security of both developed and acquired software.

...more
View all episodesView all episodes
Download on the App Store

InfoSec BitesBy HelloInfoSec