Skip to content

Certified Secure Software Lifecycle Professional (CSSLP)

Professional training. Expert instructors. Better value. No compromises.

CY-009 Live Instructor-Led Training
ISC2 5 Days 40 Hours
$2,199

Expert Training. Better Value.

Why pay $4,295 elsewhere?

Pricing shown is for individual enrollment.

Training a Team?

Ask us about group pricing, custom scheduling, and focused delivery.

Contact Us

ISC2 Certified Secure Software Lifecycle Professional (CSSLP) focuses on integrating security throughout the software development lifecycle rather than treating it as a final testing activity. It is designed for software development and security professionals who are responsible for building, assessing, deploying, or maintaining applications, along with organizations seeking to reduce software risk through more consistent development practices.

The curriculum addresses secure software concepts, lifecycle management, requirements, architecture and design, implementation, testing, deployment, operations, maintenance, and software supply chain security. Participants examine how security requirements are established, translated into design decisions, applied during development, and verified through testing. The training also covers secure deployment, vulnerability management, third-party components, supply chain risk, and the governance processes needed to maintain software security after release.

Software architects, developers, application security engineers, DevSecOps professionals, testers, and technical leaders with substantial software security responsibilities are the primary audience. ISC2 requires four years of relevant professional experience for certification, with qualifying education able to satisfy up to one year of that requirement. Organizations can use CSSLP training to improve coordination between development and security teams, strengthen secure development practices, and embed security into software delivery from initial planning through production operations.

Course Objectives

What you will learn

Domain 1: Secure Software Concepts

  • Understand core concepts.
  • Understand security design principles.

Domain 2: Secure Software Lifecycle Management

  • Manage security within a software development methodology (e.g., Agile, waterfall).
  • Identify and adopt security standards.
  • Outline strategy and roadmap.
  • Define and develop security documentation.
  • Define security metrics.
  • Decommission applications.
  • Create security reporting mechanisms.
  • Incorporate integrated risk management methods.
  • Implement secure operation practices.

Domain 3: Secure Software Requirements

  • Define software security requirements.
  • Identify compliance requirements.
  • Identify data classification requirements.
  • Identify privacy requirements.
  • Define data access provisioning.
  • Develop misuse and abuse cases.
  • Develop security requirement traceability matrix.
  • Define third-party vendor security requirements.

Domain 4: Secure Software Architecture and Design

  • Define the security architecture.
  • Perform secure interface design.
  • Evaluate and select reusable technologies.
  • Perform threat modeling.
  • Perform architectural risk assessment and design reviews.
  • Model (non-functional) security properties and constraints.
  • Define secure operational architecture.

Domain 5: Secure Software Implementation

  • Adhere to relevant secure coding practices.
  • Analyze code for security risks.
  • Implement security controls.
  • Address the identified security risks.
  • Evaluate and integrate components.
  • Apply security during the build process.

Domain 6: Secure Software Testing

  • Develop security testing strategy and plan.
  • Develop security test cases.
  • Verify and validate documentation.
  • Identify undocumented functionality.
  • Analyze security implications of test results.
  • Classify and track security errors.
  • Secure test data.
  • Perform verification and validation testing.

Domain 7: Secure Software Deployment, Operations, Maintenance

  • Perform operational risk analysis.
  • Secure configuration and version control.
  • Release software securely.
  • Store and manage security data.
  • Ensure secure installation.
  • Obtain security approval to operate.
  • Perform information security continuous monitoring.
  • Execute the incident response plan.
  • Perform patch management.
  • Perform vulnerability management.
  • Incorporate runtime protection.
  • Support continuity of operations.
  • Integrate service level objectives and service-level agreements (SLA).

Domain 8: Secure Software Supply Chain

  • Implement software supply chain risk management.
  • Analyze security of third-party software.
  • Verify pedigree and provenance.
  • Ensure and verify supplier security requirements in the acquisition process.
  • Support contractual requirements.