ISC2 CSSLP® Training Boot Camp

Transform your career in 6 days

Become a Certified Secure Software Lifecycle Professional (CSSLP). You’ll leave this boot camp with the knowledge and domain expertise needed to pass the CSSLP exam the first time you take it.

4.31 (598 ratings)

Affirm Financing available
Exam Pass Guarantee

Course essentials

Boot camp at a glance

  • Method

    Online, in-person, team onsite

  • Duration

    6 days

  • Experience

    3-5 years of experience

  • Meets 8570.1

    DoD information assurance requirements

What you'll learn

Training overview

Infosec’s CSSLP Boot camp teaches you how to incorporate security practices throughout the software development lifecycle. You’ll learn key policies, procedures and best practices related to secure software development and how to incorporate them into each phase of the development lifecycle.

You’ll leave fully prepared to earn your CSSLP certification and prove to employers that you have the knowledge and skills necessary to implement secure software development and help mitigate cyber threats.

Who should attend

Who Should Attend Image
  • Software developers
  • Software architects
  • Software engineers
  • Application security specialists
  • Penetration testers
  • Project managers
  • Anyone involved in the software development lifecycle (SDLC)

Award-winning training you can trust

Ready to discuss your training goals? We've got you covered.

Complete the form and book a meeting with a member of our team to explore your learning opportunities.

This is where the error message would go.

Step 1


Thanks! We look forward to meeting with you!

What's included

Everything you need to know

 Certification Logo
  • 90-day extended access to Boot Camp components, including class recordings
  • 100% Satisfaction Guarantee
  • Exam Pass Guarantee
  • Exam voucher
  • Free 90-day Infosec Skills subscription (access to 1,400+ additional courses and labs)
  • Knowledge Transfer Guarantee
  • Pre-study learning path
  • Unlimited practice exam attempts

What makes the Infosec CSSLP prep course different?

You can rest assured that the CSSLP training materials are fully updated and synced with the latest version of the CSSLP exam. In addition, you’ll gain access to a CSSLP prep course the moment you enroll, so you can prepare for and get the most out of your boot camp.


With 20 years of training experience, we stand by our CSSLP training with an Exam Pass Guarantee. This means if you don’t pass the exam on the first attempt, we’ll pay for your second exam at no additional cost to you!

Before your boot camp


To obtain the CSSLP certification, you must have:

  • At least four years of professional Software Development Lifecycle (SDLC) experience
  • A work history reflecting direct experience in at least one of the eight domains listed in the ISC2 CSSLP Common Body of Knowledge (CBK)

However, you can become an Associate of ISC2 by passing the exam without the required work experience.


Training schedule

Preparation (before the boot camp starts)
Infosec Skills 90 day subscription logo

CSSLP prep course

Day 1
Morning session

Secure software concepts

  • Core concepts
  • Security design principles
Afternoon session

Secure software requirements

  • Define software security requirements
  • Identify and analyze compliance requirements
  • Identify and analyze data classification requirements
  • Identify and analyze privacy requirements
  • Develop misuse and abuse cases
  • Develop security requirement traceability matrix (SRTM)
  • Ensure security requirements flow down to suppliers/providers
Evening session

Optional group & individual study

Schedule may vary from class to class

Day 2
Morning session

Secure software architecture and design

  • Perform threat modeling
  • Define the security architecture
  • Performing secure interface design
  • Performing architectural risk assessment
  • Modeling (non-functional) security properties and constraints
  • Model and classify data
  • Evaluate and select reusable secure design
  • Perform security architecture and design review
  • Define secure operational architecture (e.g., deployment topology, operational interfaces)
  • Use secure architecture and design principles, patterns and tools
Afternoon session

Secure software architecture and design continued

Evening session

Optional group & individual study

Schedule may vary from class to class

Day 3
Morning session

Secure software implementation

  • Adhere to relevant secure coding practices (e.g., standards, guidelines and regulations)
  • Analyze code for security risks
  • Implement security controls (e.g., watchdogs, file integrity monitoring (FIM), anti-malware)
  • Address security risks (e.g. remediation, mitigation, transfer, accept)
  • Securely reuse third-party code or libraries (e.g., software composition analysis (SCA))
  • Securely integrate components
  • Apply security during the build process
Afternoon session

Secure software implementation continued

Evening session

Optional group & individual study

Schedule may vary from class to class

Day 4
Morning session

Secure software testing

  • Develop security test cases
  • Develop security testing strategy and plan
  • Verify and validate documentation (e.g., installation and setup instructions, error messages, user guides, release notes)
  • Identify undocumented functionality
  • Analyze security implications of test results (e.g., impact on product management, prioritization, break build criteria)
  • Classify and track security errors
  • Secure test data
  • Perform verification and validation testing
Afternoon session

Secure software lifecycle management

  • Secure configuration and version control (e.g., hardware, software, documentation, interfaces, patching)
  • Define strategy and roadmap
  • Manage security within a software development methodology
  • Identify security standards and frameworks
  • Define and develop security documentation
  • Develop security metrics (e.g., defects per line of code, criticality level, average remediation time, complexity)
  • Decommission software
  • Report security status (e.g., reports, dashboards, feedback loops)
  • Incorporate integrated risk management (IRM)
  • Promote security culture in software development
  • Implement continuous improvement (e.g., retrospective, lessons learned)
Evening session

Optional group & individual study

Schedule may vary from class to class

Day 5
Morning session

Secure software deployment, operations and maintenance

  • Perform operational risk analysis
  • Release software securely
  • Securely store and manage security data
  • Ensure secure installation
  • Perform post-deployment security testing
  • Obtain security approval to operate (e.g., risk acceptance, sign-off at appropriate level)
  • Perform information security continuous monitoring (ISCM)
  • Support incident response
  • Perform patch management (e.g. secure release, testing)
  • Perform vulnerability management (e.g., scanning, tracking, triaging)
  • Runtime protection (e.g., runtime application self-protection (RASP), web application firewall (WAF), address space layout randomization (ASLR))
  • Support continuity of operations
  • Integrate service level objectives (SLO) and service level agreements (SLA) (e.g., maintenance, performance, availability, qualified personnel)
Afternoon session

Secure software supply chain

  • Implement software supply chain risk management
  • Analyze security of third-party software
  • Verify pedigree and provenance
  • Ensure supplier security requirements in the acquisition process
  • Support contractual requirements (e.g., intellectual property (IP) ownership, code escrow, liability, warranty, end-user license agreement (EULA), service level agreements (SLA))
Evening session

Optional group & individual study

Schedule may vary from class to class

Day 6
Morning session

Take the CSSLP exam

Schedule may vary from class to class

Unlock team training discounts

If you’re like many of our clients, employee certification is more than a goal — it’s a business requirement. Connect with our team to learn more about our training discounts.

Guaranteed results

Our boot camp guarantees

Exam Pass Guarantee

If you don’t pass your exam on the first attempt, get a second attempt for free. Includes the ability to re-sit the course for free for up to one year (does not apply to CMMC-AB boot camps).

100% Satisfaction Guarantee

If you’re not 100% satisfied with your training at the end of the first day, you may withdraw and enroll in a different online or in-person course.

Knowledge Transfer Guarantee

If an employee leaves within three months of obtaining certification, Infosec will train a different employee at the same organization tuition-free for up to one year.

Meets 8570.1 requirements

Attention DoD Information Assurance workers! This boot camp helps meet U.S. Department of Defense Directive 8570.1 requirements for department employees or contractors engaged in work related to information security.

You're in good company


The instructor was able to take material that prior to the class had made no sense, and explained it in real world scenarios that were able to be understood.

Erik Heiss, United States Air Force

I really appreciate that our instructor was extremely knowledgeable and was able to provide the information in a way that it could be understood. He also provided valuable test-taking strategies that I know not only helped me with this exam, but will help in all exams I take in the future.

Michelle Jemmott, Pentagon

The course was extremely helpful and provided exactly what we needed to know in order to successfully navigate the exam. Without this I am not confident I would have passed.

Robert Caldwell, Salient Federal Solutions

Enroll in a boot camp

September 23, 2024 - September 27, 2024

Online only | Start time: 8:30 AM (CST)

November 11, 2024 - November 15, 2024

Online only | Start time: 9:30 AM (CST)

February 3, 2025 - February 7, 2025

Online only | Start time: 8:30 AM (CST)

March 17, 2025 - March 21, 2025

Online only | Start time: 8:30 AM (CST)

June 16, 2025 - June 20, 2025

Online only | Start time: 8:30 AM (CST)