From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Accountability
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Accountability
- [Instructor] Over time, applications can generate a lot of traffic and activity. Every login, every form submission, and every search query represents someone doing something with the access that you've granted them. The question is, are they using that access appropriately? Your access controls are going to be largely preventative, designed to make sure that users can only do what they're supposed to do. Users are clever though, and so are criminals. If they find a way to do something that they should not be doing, then you need to be able to catch them in the act. There's an old Russian saying that speaks to this exact concern, "Doveryai, no proveryai." "Trust, but verify." We refer to this concept as accountability. It means that you're able to determine who did what within your app. It also means you know the exact date and time that they did. It sounds simple, right? Let's just say it's easier said than done. When it comes to accountability, you're going to live and die by your…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)