ISSAP Domain 5: Section 1: Architect for Application Security Course

58 minutes

Syllabus

Introduction to Architect for Application Security

Video - 00:04:00

This is an introduction to Domain 5 of ISSAP, Architect for Application Security.
Assess code review methodology (e.g., dynamic, manual, static)

Video - 00:21:00

Identify the current code review methodologies being used (current state) and determine where the organization wants to be (future state). Ensure that the three basics are included: traceability, documentation and secure coding.
Assess the need for application protection (e.g., Web Application Firewall, anti-malware, secure Application Programming Interface, secure Security Assertion Markup Language)

Video - 00:13:00

Identify the current application protection mechanisms which the organization employs (current state) and where they want to be (future state), paying particular attention to legacy code and FIM sharing.
Determine encryption requirements (e.g., at-rest, in-transit, in-use)

Video - 00:07:00

Identify the current encryption requirements for DAR, DIT/DIM and DIU and ascertain whether they meet the legal requirements and meet the business goals and objectives.
Assess the need for secure communications between applications and databases or other endpoints

Video - 00:09:00

Specific to DIT/DIM, determine the requirements for communication security between applications/databases/other endpoints and assess the organization's compliance with those requirements.
Leverage secure code repository

Video - 00:04:00

Assess the logic behind why the source code repository must be protected, both from an access control point of view and from a hacker point of view.

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments

Plans & pricing

Infosec Skills Personal

$299 / year

  • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Custom certification practice exams (e.g., CISSP, Security+)
  • Skill assessments
  • Infosec peer community support

Infosec Skills Teams

$799 per license / year

  • Team administration and reporting
  • Dedicated client success manager
  • Single sign-on (SSO)
    Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
  • Integrations via API
    Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
  • 190+ role-guided learning paths and assessments (e.g., Incident Response)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Create and assign custom learning paths
  • Custom certification practice exams (e.g., CISSP, CISA)
  • Optional upgrade: Guarantee team certification with live boot camps

Learn about scholarships and financing with

Affirm logo

Award-winning training you can trust