From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Legal, regulatory, and industry
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Legal, regulatory, and industry
- [Narrator] Your internal policies are a great place to start when building out your list of software security requirements, but you don't want to stop there. You should also consider the influence of external requirements on your software security efforts. Generally speaking, those external requirements are likely to fall into one of three categories: legal, regulatory, and industry. While these categories are similar in the fact that they're all external to your organization, each one has its own nuances. Legal requirements are those defined by federal, state, or local governments. The requirements tend to be broadly applicable based on where your organization operates, and they often revolve around certain data types. The Sarbanes-Oxley Act of 2002 was designed to ensure transparency and accountability for publicly traded companies in the United States. Any company who sells stock must prove at least annually that they're in compliance with this law. Failure to comply with legal…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)