CISSP Domain 8 Review / Mind Map (1 of 2) | Secure Software Development

Поділитися
Вставка
  • Опубліковано 31 лип 2024
  • Review of the major Secure Software Development concepts and terms, and how they interrelate, to help you review, guide your studies, and help you pass the CISSP exam.
    This MindMap review covers:
    00:00 Intro
    00:29 Overview
    01:04 Bake in Security
    01:26 SLC
    01:47 SDLC
    02:35 Development methodologies
    04:10 SecDevOps
    05:30 Canary deployments
    07:21 Maturity models
    08:18 APIs
    09:01 Code obfuscation
    09:52 Acquiring software
    10:44 Buffer overflows
    Other MindMaps:
    Domain 1
    Security & Risk Management: • CISSP Domain 1 Review ...
    Domain 2
    Asset Classification: • CISSP Domain 2 Review ...
    Privacy: • CISSP Domain 2 Review ...
    Domain 3
    Models and Frameworks: • CISSP Domain 3 Review ...
    Evaluation Criteria: • CISSP Domain 3 Review ...
    Trusted Computing Base: • CISSP Domain 3 Review ...
    Vulnerabilities in Systems: • CISSP Domain 3 Review ...
    Cloud: • CISSP Domain 3 Review ...
    Cryptography: • CISSP Domain 3 Review ...
    Digital Certificates, Digital Signatures & PKI: • CISSP Domain 3 Review ...
    Cryptanalysis: • CISSP Domain 3 Review ...
    Physical Security: • CISSP Domain 3 Review ...
    Domain 5
    Access Control Overview: • CISSP Domain 5 Review ...
    Single Sing-on & Federated Access: • CISSP Domain 5 Review ...
    Domain 6
    Security Assessment and Testing Overview: • CISSP Domain 6 Review ...
    Vulnerability Assessment and Penetration Testing: • CISSP Domain 6 Review ...
    Logging & Monitoring: • CISSP Domain 6 Review ...
    Domain 7
    Investigations: • CISSP Domain 7 Review ...
    Incident Response: • CISSP Domain 7 Review ...
    Malware: • CISSP Domain 7 Review ...
    Patching & Change Management: • CISSP Domain 7 Review ...
    Recovery Strategies: • CISSP Domain 7 Review ...
    Business Continuity Management (BCM): • CISSP Domain 7 Review ...
    Domain 8
    Secure Software Development: • CISSP Domain 8 Review ...
    Databases: • CISSP Domain 8 Review ...
    CISSP Master Instructor, John Berti: / jberti
    Visuals, narration and CISSP Master Instructor, Rob Witcher: / robwitcher
    Video editing by Nick: threntinfo@gmail.com

КОМЕНТАРІ • 47

  • @destcert
    @destcert  2 роки тому +7

    Our CISSP MasterClass includes your own personal CISSP mentor who will guide you to confidently passing the CISSP exam: destcert.com/CISSP

  • @ahmedcmc
    @ahmedcmc 3 роки тому +17

    All MindMap CISSP Videos are best free preparations for the Exam. Easy to digest and deliver the concept much better other than dry books.. Thanks a lot Rob for great Contribution to the Info Sec community. We really appreciate your great Job..

  • @dru3266
    @dru3266 3 роки тому +3

    This is the closest I have found to CISSP study ASMR. I love and appreciate it

  • @animeshmusic
    @animeshmusic 3 роки тому +9

    I sure hope you’re a professor because you have an uncanny ability to explain complex concepts at a simple level! The visuals help a ton! And the organization of concepts is so nice!

    • @destcert
      @destcert  3 роки тому +5

      That's lovely to hear. Thanks! And yes, my day job is teaching CISSP courses :)

  • @ganeshchavan9290
    @ganeshchavan9290 3 роки тому +7

    Hi rob,
    I glad to inform today I provisionally passed cissp exam.
    It's amazing this mind map videos for clearing my exam.
    As u told " hi I am rob witcher today going to help u pass cissp exam..."
    That's goes worked on my journey.
    Thank you for amazing videos 🙏🙏🙏

    • @destcert
      @destcert  3 роки тому +3

      Congratulations Ganesh! Well done passing the CISSP exam!
      Thanks so much for letting me know. It's great to hear these videos are helping people learn and become better security professionals!

  • @ksaholy
    @ksaholy 3 роки тому +8

    About Waterfall methedology, sybex book mentioned
    "the modern waterfall model does allow development to return to the previous phase to correct defects
    discovered during the subsequent phase. This is often known as the feedback loop characteristic of the waterfall model."
    Thank you for your great efforts.

    • @louhablas8073
      @louhablas8073 Рік тому +1

      Yes, the video is referring to the traditional waterfall model, which does not allow a return to the previous phase. As you noted, the modern/modified waterfall DOES allow return to a previous phase.

  • @odynjoku3618
    @odynjoku3618 3 роки тому +7

    Thank you for putting these together. Very well laid out.

  • @fahimm3069
    @fahimm3069 Рік тому

    Great videos Rob! Very clearly and brief to understand. thank you!

  • @nickybesters
    @nickybesters Рік тому +1

    Very concise and valuable. This ties it all together, I've been through countless hours of content which go into a lot of detail so this was so helpful in helping to see the bigger picture. Thanks, Rob 👍

  • @surajrayamajhi6811
    @surajrayamajhi6811 3 роки тому +3

    This is very helpful. Thank you for putting in so much effort.

  • @Hawk74
    @Hawk74 3 роки тому +8

    You've got some outstanding videos! I appreciate your work and sharing your knowledge, thank you.

    • @destcert
      @destcert  3 роки тому

      Thanks! My pleasure!

  • @udhay.msundaram3625
    @udhay.msundaram3625 2 роки тому

    Hello Rob , thanks for this wonderful work for society this really helped me to pass cissp exam . I cleared it just 2 days before Thankyou for ur efforts .

  • @vasanthpaths7157
    @vasanthpaths7157 3 роки тому

    Perfect snapshot! Thank you.

  • @deckydoherty
    @deckydoherty 3 роки тому +2

    These are an excellent resource.

  • @00luismartinez00
    @00luismartinez00 3 роки тому +4

    This presentation it's really helpful to add up to my current CISSP studies. Keep up the good work!

  • @teewhy0700
    @teewhy0700 3 роки тому +3

    The waterfall model was one of the first comprehensive attempts to model the software
    development process while taking into account the necessity of returning to previous phases
    to correct system faults. However, one of the major criticisms of this model is that it allows
    the developers to step back only one phase in the process. It does not make provisions for
    the discovery of errors at a later phase in the development cycle.

  • @estrategiaygestiondecibers1673
    @estrategiaygestiondecibers1673 3 роки тому +2

    Gracias por estas explicaciones

  • @ambitecturous4741
    @ambitecturous4741 2 роки тому +1

    "Life-by-Powerpoint." Mr. Witcher, you've obviously put a lot of thought and care into selecting memorable visuals. 😉

  • @waisahmadi2332
    @waisahmadi2332 3 роки тому +1

    very nicely summarized.

  • @HassanAli-bw2hh
    @HassanAli-bw2hh Рік тому

    amazing vedio Thanks

  • @AhlanWaSahlann
    @AhlanWaSahlann 3 роки тому +2

    awesome explanations, waiting for more videos..

    • @destcert
      @destcert  3 роки тому +1

      Working on them!

  • @jonathanmcneill4993
    @jonathanmcneill4993 4 роки тому +2

    I've read the McGraw Hill book on the CISSP. I've got the Sybex official ISC2 book that I'm working on now. I have not found any mention of the representational state transfer (REST) API. Thank you! This is why it is so important to use multiple sources when studying for this exam!!

    • @destcert
      @destcert  4 роки тому

      Indeed. The exam is constantly evolving!

    • @RobFire3
      @RobFire3 4 роки тому

      Know your API's: REST & SOAP.

    • @MegaJusttosee
      @MegaJusttosee 4 роки тому

      REST and SOAP are very important, buddy.

  • @strcelrau
    @strcelrau 3 роки тому

    Waterfall is presented in the OSG with the feedback loop. In that case water does go up

  • @MrRajeshpon
    @MrRajeshpon 4 роки тому +1

    Well detailed video to refresh the topic before exams

    • @destcert
      @destcert  4 роки тому

      All the best in your studies! Let me know when you pass the exam 😁

  • @bipi_S
    @bipi_S 5 місяців тому

    thanks

  • @tragicmouse1
    @tragicmouse1 3 роки тому

    Thank you for your work. I am attempting the exam soon. But I have a question, in your video, it was mentioned that the Development step is where the code is written, and there are models for it i.e waterfall, agile, spiral, devops etc, but in these methods, they have their own design, requirement gathering, testing, operations and maintenance phase; are these steps only looping in the Development stage of the SLC / SDLC? I can't connect the Waterfall or Agile phases, when out of Development stage is the Testing stage, is the SLC/SDLC testing stage the test of the entire system? Or the Waterfall stage actually spills out and is not a nested loop? I hope my question makes sense. Thank you again.

  • @AGRuwan
    @AGRuwan 3 роки тому +1

    Pls do video for SAML like kerberoes

  • @mohamedelbaz9288
    @mohamedelbaz9288 2 роки тому +1

    The info is great. Just wanna say that you speak like Teal Swan :)

  • @TheTCPTalk
    @TheTCPTalk 4 роки тому +2

    Hey I can't find domain 3 in your videos list..did you skip it?

    • @destcert
      @destcert  4 роки тому +3

      I'm working my way towards it. Next up is Domain 2, then 3, and then 4. I'll be starting into the 9 videos I have planned for Domain 3 in a couple of weeks!

  • @Telekine5i5
    @Telekine5i5 4 місяці тому

    can we do a MIND MAP for CSSLP please ?

  • @tiphotisted
    @tiphotisted 3 роки тому +2

    In waterfall you can go back one step

  • @ekon06
    @ekon06 Місяць тому

    I like this topic but its quite heavy

  • @hardikmaru3311
    @hardikmaru3311 2 роки тому +1

    Devops is not a development methodology

  • @solsticespiral6423
    @solsticespiral6423 3 роки тому

    *just an honest opinion* It's a bit dry but informative enough that I'm listening. I'm following CISSP reference guide as I go and that helps me pay attention. Good tho! TY

  • @robotron1236
    @robotron1236 7 місяців тому

    There are 8 CISSP domains and 5 of them do the exact same thing…