CISSP Certification Domain 7 & 8: The Complete Course
CISSP Certification Domain 7 & 8 - Learning Security Operations and Software Development and Security in this Course.
CISSP Certification Domain 7 & 8 - Learning Security Operations and Software Development and Security in this Course.
Welcome to this course: CISSP Certification Domain 7 & 8: The Complete Course. Security operations pertains to everything that takes place to keep networks, computer systems, applications, and environments up and running in a secure and protected manner. This course covers security in operations including physical and environmental security, equipment security, and monitoring activities. The core concepts in the operations security are covered with suitable illustrations. Security operations consists of ensuring that people, applications, and servers have the proper access privileges to only the resources to which they are entitled and that oversight is implemented via monitoring, auditing, and reporting controls. Operations take place after the network is developed and implemented. This includes the continual maintenance of an environment and the activities that should take place on a day-to-day or week-to-week basis. These activities are routine in nature and enable the network and individual computer systems to continue running correctly and securely. Software is usually developed with a strong focus on functionality, not security. This course also covers foundational concepts in various software development life cycle models, and it discusses security requirements in software development processes and assurance requirements in the software. In many cases, security controls are bolted on as an afterthought (if at all). To get the best of both worlds, security and functionality would have to be designed and integrated at each phase of the development life cycle. Security should be interwoven into the core of a product and provide protection at the necessary layers. This is a better approach than trying to develop a front end or wrapper that may reduce the overall functionality and leave security holes when the software has to be integrated into a production environment.
Did this page help you? Yes No Share Feedback