Chapter 8 of 810% of exam

Software Development Security

Domain 8 covers building security into the software development life cycle, securing the development ecosystem and pipeline, assessing software security, judging acquired software, and secure coding. NIST's Secure Software Development Framework and the OWASP Top 10 give the common vocabulary.

Security in the SDLC

Whatever the methodology, from waterfall to DevSecOps, security work is spread across the life cycle rather than bolted on at the end. The SSDF organizes it into four practice groups, and maturity models describe how consistently an organization performs it.

SSDF groups
Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), Respond to Vulnerabilities (RV).
NIST SP 800-218 §2
Toolchains
Implement supporting toolchains so security checks are automated in the development process.
NIST SP 800-218 PO.3
CMM levels
Initial, Repeatable, Defined, Managed, Optimizing.
SEI CMM for Software v1.1

Securing the development ecosystem

Code repositories, build pipelines and third-party components are all attack paths. Protect code from tampering, let customers verify what you release, and know which components you ship.

Protect code
Store all forms of code with restricted access to prevent unauthorized access and tampering.
NIST SP 800-218 PS.1
Release integrity
Make integrity verification information, such as hashes and signatures, available to acquirers.
NIST SP 800-218 PS.2.1
Components
Inventory component versions continuously and use software composition analysis to automate tracking of known vulnerabilities.
OWASP Top 10:2025 A03 Software Supply Chain Failures

Testing and responding

Static analysis reads code, dynamic testing exercises the running program, and both belong in the pipeline. After release, vulnerabilities must be received, fixed and traced to root causes so the same class of flaw is removed everywhere.

Review and test
Review or analyze human-readable code (PW.7) and test executable code (PW.8).
NIST SP 800-218 PW.7, PW.8
Intake
Gather vulnerability information from acquirers, users and public sources.
NIST SP 800-218 RV.1.1
Root cause
Analyze vulnerabilities to identify root causes and similar weaknesses.
NIST SP 800-218 RV.3

Secure coding and acquired software

Most source-level weaknesses come down to trusting input or skipping authorization on the server. Acquired software, whether COTS, open source or cloud service, needs its own assessment rather than assumed trust.

Injection
Prefer safe APIs and parameterized interfaces; add positive server-side input validation.
OWASP Top 10:2025 A05 Injection
Access control
Deny by default and enforce record ownership in server-side code; guard against insecure direct object references.
OWASP Top 10:2025 A01 Broken Access Control
Supplier requirements
Communicate security requirements to third-party suppliers of software.
NIST SP 800-218 PO.1.3

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report