Software Development Security
Domain 8 covers building security into the software development life cycle, securing the development ecosystem and pipeline, assessing software security, judging acquired software, and secure coding. NIST's Secure Software Development Framework and the OWASP Top 10 give the common vocabulary.
Security in the SDLC
Whatever the methodology, from waterfall to DevSecOps, security work is spread across the life cycle rather than bolted on at the end. The SSDF organizes it into four practice groups, and maturity models describe how consistently an organization performs it.
Securing the development ecosystem
Code repositories, build pipelines and third-party components are all attack paths. Protect code from tampering, let customers verify what you release, and know which components you ship.
Testing and responding
Static analysis reads code, dynamic testing exercises the running program, and both belong in the pipeline. After release, vulnerabilities must be received, fixed and traced to root causes so the same class of flaw is removed everywhere.
Secure coding and acquired software
Most source-level weaknesses come down to trusting input or skipping authorization on the server. Acquired software, whether COTS, open source or cloud service, needs its own assessment rather than assumed trust.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.