EH-Net

Ethical Hacking Discussions and Related Certifications => Security => Topic started by: johndkent on July 01, 2011, 07:38:12 AM



Title: (ISC)2 CSSLP
Post by: johndkent on July 01, 2011, 07:38:12 AM
Has anyone taken the Certified Secure Software Lifecycle Professional (CSSLP) exam?  The Official (ISC)2 Guide to the CSSLP has finally been published so I'm planning to do some self-study (the class at TakeDownCon Dallas was cancelled, unfortunately).  I was curious about your impression of the difficulty of the exam and your assessment of the benefit of the knowledge gained from preparation.

Thank you


Title: Re: (ISC)2 CSSLP
Post by: csfergu on August 11, 2011, 07:22:23 AM
I have not taken it yet but plan to do so in the next two months. I did pick up the official guide and have been working through it. Debating whether or not the official practice exams are worth the price.


Title: Re: (ISC)2 CSSLP
Post by: tturner on August 11, 2011, 07:50:13 AM
Is it more focused on the SDLC or does it cover more technical topics in detail? Common programming mistakes, validating inputs, etc? I've had my eye on http://www.sans.org/security-training/defending-web-applications-security-essentials-1442-mid (obviously focused on web apps) but am also curious about CSSLP and other offerings.


Title: Re: (ISC)2 CSSLP
Post by: csfergu on August 11, 2011, 09:10:49 AM
It is primarily focused on the SDLC and where security fits in. The official book does mention the more technical topics like SQLi, validation, etc., but it is brief and the focus is more on the high-level SDLC topics.


Title: Re: (ISC)2 CSSLP
Post by: amol_d on December 26, 2012, 12:44:07 AM
Just passed CSSLP. I am glad i took it. The format and quetion structure is very similar to CISSP as you would expect (ie you either know or you dont, not like CISA where they play arround with the English language to make it trickier)
I think it is very very relevant to those who are into secure SDLC. While going through the material I already got a ton of tips on what i should be doing to making my info-sec reviews better. I from studied the ISC2 official guide to CSSLP .


Title: Re: (ISC)2 CSSLP
Post by: amol_d on December 26, 2012, 12:46:47 AM
ALso, quite liked the Pearson-Vue centers and format. Very different from the CISSP i took 5 years ago where you mark circles with a pencil. Now they have computerized tests, instant results and noise cancelling earphones. cool! 8)