From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,100 courses taught by industry experts.
Analyzing third-party software security
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Analyzing third-party software security
- [Instructor] It's rare that you have the tools, the time, and the permission to run third-party software solutions through the same security regimen that you apply to internally developed applications. There are certain nuances to analyzing the security of third-party software. As I mentioned in an earlier video, the likelihood is somewhat low that you'll be able to run a vulnerability scan against a third-party application. If it's a commercial off-the-shelf application, you'll be limited to black box testing or testing with limited permissions or visibility. Chances are you won't have the source code for on-premise applications, and you'll be prohibited from scanning SaaS applications to minimize the risk of breaking components while other customers are using them. Instead of running those vulnerability scans yourselves, you'll be better off if you let the partner perform all of their own internal security testing. After all, you don't need to run the scans. You just need to know…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)