Chapter summary

  • Security should permeate every phase of the software development life cycle (SLDC). The SDLC phases include project initiation, functional design, system design, software development, installation/test, operational maintenance, and disposal/end of life.

  • Change control and configuration management help stabilize the software development environment.

  • Separation of duties to avoid conflicts of interest should be implemented within the software development environment.

  • Component Object Model (COM) and Distributed Component Object Model (DCOM) allow processes to share processes and data in Microsoft applications. Object request brokers (ORB) and common object request brokers architecture (CORBA) allow processes to share processes and data ...

Get CISSP Training Kit now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.