From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,100 courses taught by industry experts.
Attack surface evaluation
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Attack surface evaluation
- [Instructor] By minimizing your application's attack surface, you can reduce both the likelihood and impact of any attacks launched against your application. Before you can take action to reduce that risk though, you'll want to perform an attack surface evaluation. Attack surface evaluation is the process of identifying all the parts of your application and the underlying app infrastructure that an attacker might target. Once you've got a solid idea of what that attack surface looks like, you'll also want to identify any mitigating controls you already have in place. This will help you pinpoint any missing controls that you may want to implement. Consider your application from an attacker's point of view. Specifically, I want you to think like an unauthorized outsider. You are sitting at your laptop staring at the login page for an app that you plan to attack. Where do you start? One area of your application's attack surface is the login interface, as well as all the usernames…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)