Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. FFS

FFS

Scheduled Pinned Locked Moved The Lounge
designsysadminsecuritytestingbusiness
27 Posts 14 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • realJSOPR realJSOP

    New DoD requirement for software developers that MUST be fulfilled by July 2019... CSSLP (certified secure software lifecycle professional) is a certification from (ISC)2 that focuses on application security within the software development lifecycle (SDLC). Launched in 2008, the CSSLP certification is designed for programmers, project managers, IT analysts or engineers involved in the SDLC. The certification's curriculum focuses on application vulnerabilities, risk and compliance issues that arise during the application development lifecycle and is broken down into eight domains: •Secure Software Concepts •Secure Software Requirements •Software Design •Secure Software Implementation/Coding •Secure Software Testing •Software Acceptance, Software Deployment •Operations, Maintenance and Disposal •Supply Chain and Software Acquisition CSSLP is intended to help candidates validate their expertise in application security, be able to better handle application vulnerabilities and demonstrate a working knowledge of application security. In order to be considered for the CSSLP certification, candidates must have at least four years cumulative paid full-time work experience in at least one of the eight domains of the CSSLP. Alternatively, candidates can substitute a year of this work experience with a four-year college degree in a related field. The CSSLP exam takes four hours to complete and consists of 175 multiple choice questions. Candidate need to achieve a minimum of 700 out of 1000 points to pass the exam and gain the certification.

    ".45 ACP - because shooting twice is just silly" - JSOP, 2010
    -----
    You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
    -----
    When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

    S Offline
    S Offline
    SkysTheLimit
    wrote on last edited by
    #18

    Does this apply to ALL software developers working on DoD contracts or just those in certain roles?

    realJSOPR 1 Reply Last reply
    0
    • M MarkTJohnson

      175 question 1000 points. Doesn't divide evenly. Try to find out which questions are the more weighty ones and focus on that material.

      L Offline
      L Offline
      Lost User
      wrote on last edited by
      #19

      1 point for each question, 825 for getting your name right?

      1 Reply Last reply
      0
      • S SkysTheLimit

        Does this apply to ALL software developers working on DoD contracts or just those in certain roles?

        realJSOPR Offline
        realJSOPR Offline
        realJSOP
        wrote on last edited by
        #20

        From what I was told, it's all developers.

        ".45 ACP - because shooting twice is just silly" - JSOP, 2010
        -----
        You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
        -----
        When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

        S J 2 Replies Last reply
        0
        • M MarkTJohnson

          175 question 1000 points. Doesn't divide evenly. Try to find out which questions are the more weighty ones and focus on that material.

          realJSOPR Offline
          realJSOPR Offline
          realJSOP
          wrote on last edited by
          #21

          CompTIA does this as well for their security crap...

          ".45 ACP - because shooting twice is just silly" - JSOP, 2010
          -----
          You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
          -----
          When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

          1 Reply Last reply
          0
          • realJSOPR realJSOP

            From what I was told, it's all developers.

            ".45 ACP - because shooting twice is just silly" - JSOP, 2010
            -----
            You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
            -----
            When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

            S Offline
            S Offline
            SkysTheLimit
            wrote on last edited by
            #22

            Thanks. And good luck in your new job :-)

            1 Reply Last reply
            0
            • realJSOPR realJSOP

              This is DoD wide. It doesn't matter what DoD contract I'm on.

              ".45 ACP - because shooting twice is just silly" - JSOP, 2010
              -----
              You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
              -----
              When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

              D Offline
              D Offline
              dandy72
              wrote on last edited by
              #23

              So don't you have this entire certification stack already? I mean, this isn't your first DoD job, right?

              1 Reply Last reply
              0
              • M Marc Clifton

                And does all that time and effort and taxpayer cost actually improve application security????

                Latest Article - A Concise Overview of Threads Learning to code with python is like learning to swim with those little arm floaties. It gives you undeserved confidence and will eventually drown you. - DangerBunny Artificial intelligence is the only remedy for natural stupidity. - CDP1802

                D Offline
                D Offline
                dandy72
                wrote on last edited by
                #24

                Marc Clifton wrote:

                And does all that time and effort and taxpayer cost actually improve application security????

                Consider the reported breaches. Draw your own conclusions. (now, add the _un_reported breaches - that should re-enforce your guess)

                1 Reply Last reply
                0
                • realJSOPR realJSOP

                  From what I was told, it's all developers.

                  ".45 ACP - because shooting twice is just silly" - JSOP, 2010
                  -----
                  You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
                  -----
                  When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

                  J Offline
                  J Offline
                  jackbrownii
                  wrote on last edited by
                  #25

                  And a corollary question: Does this apply to outside suppliers to DoD, or, just DoD employees?

                  realJSOPR 1 Reply Last reply
                  0
                  • J jackbrownii

                    And a corollary question: Does this apply to outside suppliers to DoD, or, just DoD employees?

                    realJSOPR Offline
                    realJSOPR Offline
                    realJSOP
                    wrote on last edited by
                    #26

                    DoD civilians and contractors that are developers.

                    ".45 ACP - because shooting twice is just silly" - JSOP, 2010
                    -----
                    You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
                    -----
                    When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

                    1 Reply Last reply
                    0
                    • realJSOPR realJSOP

                      New DoD requirement for software developers that MUST be fulfilled by July 2019... CSSLP (certified secure software lifecycle professional) is a certification from (ISC)2 that focuses on application security within the software development lifecycle (SDLC). Launched in 2008, the CSSLP certification is designed for programmers, project managers, IT analysts or engineers involved in the SDLC. The certification's curriculum focuses on application vulnerabilities, risk and compliance issues that arise during the application development lifecycle and is broken down into eight domains: •Secure Software Concepts •Secure Software Requirements •Software Design •Secure Software Implementation/Coding •Secure Software Testing •Software Acceptance, Software Deployment •Operations, Maintenance and Disposal •Supply Chain and Software Acquisition CSSLP is intended to help candidates validate their expertise in application security, be able to better handle application vulnerabilities and demonstrate a working knowledge of application security. In order to be considered for the CSSLP certification, candidates must have at least four years cumulative paid full-time work experience in at least one of the eight domains of the CSSLP. Alternatively, candidates can substitute a year of this work experience with a four-year college degree in a related field. The CSSLP exam takes four hours to complete and consists of 175 multiple choice questions. Candidate need to achieve a minimum of 700 out of 1000 points to pass the exam and gain the certification.

                      ".45 ACP - because shooting twice is just silly" - JSOP, 2010
                      -----
                      You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
                      -----
                      When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

                      G Offline
                      G Offline
                      Gary Wheeler
                      wrote on last edited by
                      #27

                      Makes me glad I left the world of defense contracting behind 30 years ago.

                      Software Zen: delete this;

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups