CSSLP.AO1
CSSLP Course with Hands-on Labs
Prepare for the CSSLP certification. Learn everything you need to know from the early planning stages to secure deployment and maintenance.
- Practice in 40 Hands-On Labs — nothing to install
- 22 Interactive Lessons and 135 topics mapped to the official exam objectives
- 345 Practice Test Questions and 2 Full Length Tests
Expert Self-paced · 1 year access 4.4/5 (6 Reviews)
40 Hands-On LiveLabs
Practice real IT tasks in guided environments.
- Real environments
- Auto-graded
- No installation
01 / Skills you'll get
What you will be able to do
Discover the fully-composed, CSSLP course, designed to help you conquer the exam seamlessly. Get access to over 300 collections of curated practice questions, covering all eight domains, including secure software concepts, secure software requirements & many more.
Go beyond basic security awareness and get hands-on with threat modeling, risk management, secure coding, and security testing, just like top-tier software teams do. Then, learn to align your development process with industry standards like OWASP, NIST, and ISO.
- Secure Software Design - Apply threat modeling, attack surface reduction, and secure architecture principles during the design phase.
- Defensive Coding Practices - Implement secure coding techniques to prevent vulnerabilities like buffer overflows, injection attacks, and improper error handling.
- Risk and Compliance Management - Evaluate risks, align with regulatory standards (e.g., NIST, GDPR), and ensure secure governance across the SDLC.
- Secure Deployment and Maintenance – Manage secure software releases, DevOps integration, patching, and ongoing operational security.
- General Security Concepts - Understanding the security design tenets & discovering the access control modes.
Target Career Roles
- Software Architect
- Software Engineer
- Software Developer
- Application Security Specialist
02 / Lessons & labs
See exactly what you will learn and practice
Lessons
22 Interactive Lessons · 135 topics01 Introduction 5 topics +
- Why Focus on Software Development?
- The Role of CSSLP
- How to Use This Course?
- The Examination
- CSSLP (2020)
02 General Security Concepts 4 topics · 3 LiveLab +
- General Security Concepts
- Security Models
- Adversaries
- Lesson Review
3 LiveLab in this lesson — see the labs panel →
03 Risk Management 6 topics · 1 LiveLab +
- Definitions and Terminology
- Types of Risk
- Governance, Risk, and Compliance
- Risk Management Models
- Risk Options
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
04 Security Policies and Regulations 8 topics · 3 LiveLab +
- Regulations and Compliance
- Legal Issues
- Privacy
- Security Standards
- Secure Software Architecture
- Trusted Computing
- Acquisition
- Lesson Review
3 LiveLab in this lesson — see the labs panel →
05 Software Development Methodologies 5 topics · 3 LiveLab +
- Secure Development Lifecycle
- Secure Development Lifecycle Components
- Software Development Models
- Microsoft Security Development Lifecycle
- Lesson Review
3 LiveLab in this lesson — see the labs panel →
06 Policy Decomposition 4 topics · 1 LiveLab +
- Confidentiality, Integrity, and Availability Requirements
- Authentication, Authorization, and Auditing Requirements
- Internal and External Requirements
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
07 Data Classification and Categorization 6 topics · 2 LiveLab +
- Data Classification
- Data Ownership
- Labeling
- Types of Data
- Data Lifecycle
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
08 Requirements 5 topics · 2 LiveLab +
- Functional Requirements
- Operational Requirements
- Requirements Traceability Matrix
- Connecting the Dots
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
09 Design Processes 7 topics · 1 LiveLab +
- Attack Surface Evaluation
- Threat Modeling
- Control Identification and Prioritization
- Risk Assessment for Code Reuse
- Documentation
- Design and Architecture Technical Review
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
10 Design Considerations 3 topics · 1 LiveLab +
- Application of Methods to Address Core Security Concepts
- Interfaces
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
11 Securing Commonly Used Architecture 8 topics · 3 LiveLab +
- Distributed Computing
- Service-Oriented Architecture
- Rich Internet Applications
- Pervasive/Ubiquitous Computing
- Mobile Applications
- Integration with Existing Architectures
- Cloud Architectures
- Lesson Review
3 LiveLab in this lesson — see the labs panel →
12 Technologies 13 topics · 4 LiveLab +
- Authentication and Identity Management
- Credential Management
- Flow Control (Proxies, Firewalls, Middleware)
- Logging
- Data Loss Prevention
- Virtualization
- Digital Rights Management
- Trusted Computing
- Database Security
- Programming Language Environment
- Operating Systems
- Embedded Systems
- Lesson Review
4 LiveLab in this lesson — see the labs panel →
13 Common Software Vulnerabilities and Countermeasures 10 topics · 2 LiveLab +
- CWE/SANS Top 25 Vulnerability Categories
- OWASP Vulnerability Categories
- Common Vulnerabilities and Countermeasures
- Input Validation Failures
- Common Enumerations
- Virtualization
- Embedded Systems
- Side Channel
- Social Engineering Attacks
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
14 Defensive Coding Practices 7 topics · 2 LiveLab +
- Declarative vs. Programmatic Security
- Memory Management
- Error Handling
- Interface Coding
- Primary Mitigations
- Learning from Past Mistakes
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
15 Secure Software Coding Operations 6 topics · 1 LiveLab +
- Code Analysis (Static and Dynamic)
- Code/Peer Review
- Build Environment
- Antitampering Techniques
- Configuration Management: Source Code and Versioning
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
16 Security Quality Assurance Testing 10 topics · 3 LiveLab +
- Standards for Software Quality Assurance
- Testing Methodology
- Functional Testing
- Security Testing
- Environment
- Bug Tracking
- Attack Surface Validation
- Testing Artifacts
- Test Data Lifecycle Management
- Lesson Review
3 LiveLab in this lesson — see the labs panel →
17 Security Testing 9 topics · 2 LiveLab +
- Scanning
- Penetration Testing
- Fuzzing
- Simulation Testing
- Testing for Failure
- Cryptographic Validation
- Regression Testing
- Impact Assessment and Corrective Action
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
18 Secure Lifecycle Management 4 topics · 1 LiveLab +
- Introduction to Acceptance
- Pre-release Activities
- Post-release Activities
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
19 Secure Software Installation and Deployment 3 topics · 1 LiveLab +
- Secure Software Installation and Its Subsequent Deployment
- Configuration Management
- Lesson Review
1 LiveLab in this lesson — see the labs panel →
20 Secure Software Operations and Maintenance 5 topics · 2 LiveLab +
- Secure Software Operations
- The Software Maintenance Process
- Secure DevOps
- Secure Software Disposal
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
21 Supply Chain and Software Acquisition 6 topics · 2 LiveLab +
- Supplier Risk Assessment
- Supplier Sourcing
- Software Development and Testing
- Software Delivery, Operations, and Maintenance
- Supplier Transitioning
- Lesson Review
2 LiveLab in this lesson — see the labs panel →
22 Appendix: Key Terms 1 topics +
- Glossary
Hands-On Labs Our edge
40 LiveLabs- Understanding Security Design Tenets
- Discussing About Access Control Models
- Understanding Information Flow Models
- Understanding Annualized Loss Expectancy
- Understanding Compliance-Based Assessment Regulations
- Understanding PII and PHI
- Understanding National Institute of Standards and Technology
- Discussing About Software Development Methodologies
- Understanding Secure Development Lifecycle Components
- Understanding Software Development Models
- Understanding Access Control Mechanisms
- Understanding Data Classification Types
- Understanding Data Ownership Roles
- Understanding Functional Requirements
- Understanding the Requirements Traceability Matrix
- Understanding Documentation
- Discussing About Security Design Considerations
- Understanding Distributed Computing Terms
- Understanding the Enterprise Service Bus
- Understanding Cloud Service Models
- Understanding X.509 Digital Certificate Fields
- Understanding Flow Control Technologies
- Understanding Syslog
- Understanding Trusted Computing Elements
- Discussing About Software Vulnerabilities and Countermeasures
- Understanding the Buffer Overflow Attack
- Understanding Imperative and Declarative Securities
- Understanding Memory Management
- Understanding Code Analysis Types
- Discussing About Security Quality Assurance Testing Methods
- Understanding Functional Testing Types
- Understanding Security Testing Types
- Understanding the Attack Surface Analyzer
- Understanding Regression Testing
- Understanding Various Forms of Testing
- Understanding Bootstrapping
- Understanding Operations/Maintenance Activities
- Understanding the Software Disposal Process
- Discussing About Supplier Risk Assessment
- Understanding Service Level Agreements
03 / Exam details
CSSLP Course with Hands-on Labs Details
Pass the (ISC)² CSSLP exam with the Certified Secure Software Lifecycle Professional (CSSLP) course and lab. The lab can be mapped to any course, textbook, or training, therefore, adding value and a hands-on component to training. The CSSLP training guide provides skills for the CSSLP exam topics and expertise in the areas such as security design principles, threat modeling, secure interface design, architectural risk assessment, code for security risks, dynamic application security testing (DAST), and many more.
Ready to take the exam?
Add your official CSSLP.AO1 exam voucher to your order.
Official Voucher · Fast delivery · Retake bundle available04 / FAQs
Questions before you start
What is a Certified Secure Software Lifecycle Professional CSSLP?+
Is CSSLP certification worth it?+
Which is better, CISSP or CSSLP?+
What is the exam registration fee?+
Where do I take the exam?+
What is the format of the exam?+
What are the pre-requisites of the exam?+
How many questions are asked in the exam?+
What is the duration of the exam?+
What is the passing score?+
What is the exam's retake policy?+
Here is the retake policy:
- If you don’t pass the exam the first time, you can retest after 30 days.
- If you don’t pass a second time, you can retest after an additional 90 days.
- If you don’t pass a third time, you can retest after 180 days from your most recent exam attempt.
What is the validity of the certification?+
Where can I find more information about this exam?+
CSSLP: Secure Software. Certified.
Certify your software skills with uCertify’s CSSLP course & lead your way into application security.
- 1 year of full access
- 40 LiveLab included
- Certificate of completion
No credit card required