Back to Domains
💻Domain 8

Software Development Security

11%Exam Weight
5Subdomains
8.1

Understand and integrate security in the SDLC

Key Concepts

AgileWaterfallDevOpsDevSecOpsScaled AgileCMMSAMMOperationsMaintenanceChange managementIPT
8.2

Identify and apply security controls in software development ecosystems

Key Concepts

Programming languagesLibrariesTool setsIDERuntimeCI/CDSoftware CMCode repositoriesSASTDASTSoftware composition analysisIAST
8.3

Assess the effectiveness of software security

Key Concepts

AuditingLogging changesRisk analysisRisk mitigation
8.4

Assess security impact of acquired software

Key Concepts

COTSOpen sourceThird-partyManaged servicesCloud servicesSaaSIaaSPaaS
8.5

Define and apply secure coding guidelines and standards

Key Concepts

Security weaknessesVulnerabilitiesAPI securitySecure coding practicesSoftware-defined security