| More

A Look at ISC2's CSSLP Certification Program

ISC2 recently created a new certification program for security professionals: the Certified Secure Software Lifecycle Professional (CSSLP) certification. The CSSLP certification is the result of increased security risks involving applications. This credential validates software developers’ skills as they relate to software security. The CSSLP program strives to establish best secure software development practices in order to combat the proliferation of software threats and vulnerabilities while also validating the credential holder’s expertise in this area.

unlimited online IT training library

This new certification program is rigorous with stringent requirements. CSSLP candidates must have either four years of software development lifecycle experience or three years of experience plus a bachelor’s degree in an information technology field in order to be accepted into the program. After acceptance, candidates must pass a certification exam, earn an endorsement from a current ISC2 member, and adhere to the code of ethics prescribed by the ISC2. From there, continuing education is required to maintain this prestigious certification.

Who should pursue a CSSLP certification? Software engineers, analysts, developers, architects, programmers, quality assurance testers, project managers, and other IT professionals involved in the lifecycle of software. The Certified Secure Software Lifecycle Professional program is built upon seven domains spanning the entire software lifecycle from concept to disposal:

  • Secure software concepts
  • Secure software requirements
  • Secure software design
  • Secure software implementation/coding
  • Secure software testing
  • Software acceptance
  • Software deployment, operations, maintenance, and disposal

The CSSLP certification exam costs just under $600 and is one of the first ISC2 exams to be offered in a computer-based testing format. The expense of the exam coupled with the tough questions covering all seven domains makes CSSLP training an absolute must.

Earning the CSSLP certification puts software developers in a league of their own. Since software exploits occur on a global scale, the need for developers capable of developing secure software applications is growing rapidly. With roughly 70 percent of security vulnerabilities occurring at the application layer, the threat is real and urgent. Companies recognize that a CSSLP credential holder has the expertise to develop secure software according to established practices outlined by ISC2.

Because hackers and malicious developers are constantly searching for ways to exploit software, the days of reacting to threats are numbered. ISC2’s CSSLP program demonstrates that the IT industry is moving toward a more proactive model, ensuring that new applications are no longer vulnerable through the establishment of best practices and Certified Secure Software Lifecycle Professionals.