Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
In this episode, Shon will talk about the following items that are included within Domain 8 - Software Development Security of the CISSP Exam:
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Infosec Industry
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/software-development-security/#gref
OWASP
file:///C:/Users/gerbersa/Downloads/SAMM_Core_V1-1-Final-1page.pdf
SYNK.IO
https://snyk.io/blog/ten-git-hub-security-best-practices
National Cyber Security Centre
Transcript:
…Hey all is Sean Gerber again with reduced cyber risk How are you all doing this Beautiful beautiful morning I hope things are going well in your part of the globe in this big shiny blue marble, things are going awesome in Wichita Kansas Yes The small little town of Wichita Kansas. it's going well I can not complain at all It's a beautiful summer day School's getting ready to get started and my kids are getting ready to go back to school which is an awesome thing Very very cool. It a one of those situations in your life when you have 50 if and when you have ever have children out there, kids are great most days other days, not so much And so when it comes to going back to school, most parents will just glee with be or be super happy with glee. Yeah that doesn't really good word there but anyway they're really super happy because of the fact that the kids are no longer at home And they're now focused on school. So yeah it's a it's a good thing. Well today we're going to be talking about software development And how old is this? around that? And you'll see many things that have occurred recently It was just a recent breach that hit with that. capital one here in the United States. And they said there was probably I don't know how many millions of people were affected by that And so therefore what ended up happening is is, there there was an insider threat issue Well the today we're not gonna talk about the insider We're going to talk more about the software development, but in the case of when you're creating apps or crew from a Your websites whether you're creating apps for the app store that go into the Google play or iTunes. All of that needs to have some level of software development security built into it. And so there are some key aspects we're going to go into, as it relates to doing that. Along with that is going to be the main things that you're going to have to know for the CISSP exam as you know reduce cyber risk My ultimate. Plan is is to be able to give you that CISSP training You need to pass the CIS S. The first time again we want go into that If you want to pass this I know this test is a bugger din They're done that We're going to have some next upcoming episodes We're gonna talk a little more about the exam. But bottom line is is this test is a bugger and I failed it The first time I studied my butt off for that test I studied basically three months just self study just to go put, pass the test because at the time there there were bootcamps but I didn't have the funds to be able to go pay for a bootcamp. And so I've studied it. And it was actually good that I studied just because of the fact that, it it helped me get a good knowledge of what I deal with on a daily basis. But the cool part about knowing the CISSP and passing the exam the first time is the fact that you will utilize those skills on a daily basis as a CSO, for a large multinational So those are things that consider is that the good thing is just. Just by taking the test is the first step And the examiner is the first step in the whole road to make becoming a cyber security professional. And so therefore it's it's imperative that you get these foundations and you know, fundamentals. And studying too much. Of test questions is very important you know just to understand what are they going to ask for and how they're going to ask. But those test questions are designed mainly to help you as you go through them. Understand the questions and how would they answer How would they. Question you or how would they provide the information for you so that the answers you provide are the right ones. But again Canada has already addressed but the cool part about studying for the CISSP is the fact that you used to learn a lot of good stuff. Well today we're going to learn about software development and the security that goes into that. So when I talk to my SSP cybersecurity integration This is the area that I grabbed some information from the internet, like an article or so forth. And this one is software development life cycle and we'll get into that And that's an interesting piece that you should understand your software development life cycle from beginning to end So from the beginning when it was conceived, Junior beautiful mind to when it dies and is rotting in the ground. So that's the, in some cases some of these apps. I mean I've got apps that were in our environment that are. the 1970s So they never die They just get a little aged. A CISSP. Training We're gonna talk about integrate security in the software development life cycle high burn integrate that and domain eight. And then the CISSP exam questions are obviously around development security and S D L C. All right Let's get get into it…Yeah So this is CIS S P cybersecurity integration This is the InfoSec Institute reference and I that's the who we're going to be calling up today from their website. And they're going to talk we talk about eight.one software development life cycle This is if you are, have the CISSP. The ISC squared, document that focuses on the different sub chapters around the ISC This is eight.one that's called out in that document. this is software development life cycle. Okay As I talked about in the intro applications are becoming more and more complex and therefore we're seeing these eggs that are tied together Now in the past you would have, you had just an app that let's just I say the past that's so distant past. Where it was. a year just your app store was set up with iTunes or with Google play And you had that was your app, or you had you'd build some sort of application that had a offering a ser saw a software as a service where you'd log into a web portal and you would have access to it that way. Now what ends up happening is as these applications are becoming more complex because you have edge computing that's dealing with Amazon AWS. You have your apps that you put on your phone and your phone. These things are extremely powerful So therefore that is able to come do massive computations So as technology continues to grow and get faster and faster these applications are growing in size and complexity. as well And so security needs to be a key factor in when you're successful implementation. of your application now whether this is an intentional or unintentional, it really doesn't matter The fact of it is you got to do it and you really need to look at how you keep software embedded within your environment. Now software and hardware control are extremely important And so if you're to put any sort of app out there at all, you need to have these controls in place. Now as you're dealing with Sophos. Some development control system development controls that are needed for the CISSP exam. There's some key things you need to keep in mind. Now system development steps need for creating modifying our maximizing information system So you need to have steps in place. That are going to be used to help when you're dealing with creating modifying or maximizing your information system That's a key term that you're going to run into. On the CISSP. And you need to have a formal activities set up for development so that you're heavy Like in case of myself I have a development team. They worked for me. They work out of India. And they do a great job and they do an awesome job and they have a ability to do development. And they're in the process of building out an entire suite of things that they need to do from their initial development products to CIC D to automated testing So on and so forth all that needs to be put in place. Well when you're dealing with that you also need to have some level of security built into it as well. and you need to create development standards around this coding and we've run into this with third parties. So if I have a third party that helps me and they provide some sort of coding than what is the standard by which they're developing their coats. so that's an important piece of this is that what are the aspects from the development standards? How can they do this? Now it could be as simple as a checklist They could be. My naming convention is this, we have we do have, we do fuzz testing on the application when it's done. we have you know all these little steps can be built into their process and they just go through it step by step. now I have noticed the challenges that go into this because the developers are they get paid They're incentivized to develop quickly and to develop, with good code but develop quickly And so therefore, Sometimes we don't want to take the time to do the initial steps to run it through a scanning engine, to make sure that it does that it works So those are those are conditions that you need to help in talk to your people about and ensure that they're connected with it. And then oh wasps Sam core model Now OSP is an organization that's on a that provides development for web applications. And it's basically a web applications And what are the aspects around securing those web applications? So you can go to old wasp and check it out online They have a whole laundry list of things you can use specifically for ensuring that your product is properly secured your application. I mean they have all kits from scanners to best practices I mean it's a really good place If you are a application developer and you're looking to incorporate security within your environment. they have a software assurance model That's the Sam the software assurance maturity model. And it's basically an open framework and we like to talk about frameworks but…realistically it's a guide or a checklist little checklist is a little bit too tight but it's more of a guide to formulate a strategy around applications and events evaluates the organization's existing security practices while puts in well-defined iterations for their software. they did demonstrates concrete improvements and it measures the security. activity So did the bottom line is it breaks it down for you? To be able to put security into your right now your current process. So it's just a good framework and a good checklist to go by. the highly recommend checking out Oh Wass but they have a great product out there and you will be. It will be called upon it on the CISSP. Now they may not call it the old hospice. Specifically, but they're 20 best practices that they have are we'll be we'll be called out specifically within the CIS. Those prac those best practices coding practices You you may see that…Now their top 10 project proactive controls of this is of 2016 first one is verify the security early on often obviously right But you need to stay on top of it. but rather than having something go into production and then have to do scans for it. parametize queries and co data validate all inputs That's a huge one there where you have inputs that are going in for a form field. And you validate that that yeah this I want a date of birth to go in here and I don't want Java code to be put into your I want just date of birth. That needs to be a. Input validation step that needs to be. implement identity and authentication controls huge, implement appropriate access controls protect the data again Now if you're dealing with applications that are just basic wonky data. That may not be such an important step However if you're dealing with any sort of personal data or data for your company that's considered confidential. and if you're building an app that is for somebody else you need to consider that, would that data be, be possibly considered confidential, then you need to look at protecting the data. you need to implement logging and intrusion detection. this is when we had last week from talking about logging. Lever security frameworks and libraries and then air and exception handling. So those top 10 if you did those that would do is dramatically reduce the risk to your sites. and what would end up happening is is you'd put you in a much better position as it relates to your site being affected. Bye. And it hackers are the like, Now as you're dealing with the SDLC there are some key aspects to keep in mind. one is planet our planning and requirement gathering You need to understand when you're dealing with your device. what are the requirements around it? Also architecture and design How do you designing your application and your software out there What is the purpose behind it? And then how do you make sure that it's maintained be updated? How do you update it How is that Is that built into the overall development strategy? test planning How do you test strategy over development code So how do you build that out till you're going to test to ensure that it does not like your input validations What will you put in there to ensure that the wrong input validations don't get put in and they could run potentially run code on your server? Coding and implementation ensuring code is complete by dividing into various modules. Testing and deployment, and that would be product development based on requirements. And then your release and maintenance your final product release and its maintenance and then maintaining that product. but again you have to begin this from the beginning of when they have the light of the application or the software is born to when it dies or it guess what It may not die unless you kill it. Especially we're dealing with software as a service you can kill these things but if you go out individual programs that are going out. That kind of stuff. it stays around forever So just consider that whatever you make. What is the way you're going to be able to update it And do you want to deal with that headache for a long period of time? Now One thing also about the CIS CIS. they talk about SDLC models that are covered in the CISSP. Now the most common are there there's various comments that are old or various models that are open and I'm going to go over some of these right now But, the main one that I deal with is a. scrum and you'll see that model here in just a little bit. I should say agile and that's crumbs a method of doing it It's actually, because scrum is like with a rugby, but no it's agile the agile method And we'll get into that just here in a second. A waterfall model This is the most common model And it's typically been used by many in the past And this basically basically comes down to as you finish one phase and then you go on to the next, but there's not much room for making changes to the waterfall model You have to wait until the whole process is done. Before you can go Meg, go back and make changes So if you notice that there's changes. While you're in the middle of the of the sprint with the waterfall model There's very little leeway to go back and make changes to it And you have to basically come back around after the whole thing is done. the V-shaped model was just very key verification and validation model and it's very similar to the waterfall but each phase has a testing phase. So the good piece of that is you don't wait till the end to find that you have issues. You each phase we'll give you some sort of testing and then you can make you put that in the backlog and then make iterations to that. But it is still though the overall project If you have like five sprints for this one project. you may get all the way through the project and then realize okay now I get you to go back and fix those changes. the iterative model which has repletion and improvement And basically that comes back in it replete rev repeats it. And then it improves it and it takes care of those things It's set of requirements that are tested and implemented. And you basically are You're iterating you're going back and forth back and forth And the new various versions are based on new and inner. versions of the software. So as draft software gets updated. A new iteration as a crooner occurred, then they come back and make changes and it just keeps going on that process. it's a very it gets you a very viable product early So if you're dealing with the VIP which is your VA viable product, that's a very good point It gets you there in a very quick period of time but it may take a lots of resources to do that because there's a lot of things that are going on especially if you're having to iterate it over and over again. And again these models are designed not to be One is the only one you do. the they're designed to depending upon your situation which model would you use The waterfall waterfall model. Oh waterfall the V-shape model, or the inner of model. Now we have the spiral model Now this works in an iterative model basically starts by continually repeating it over and over and over again, but it kind of goes out It allows for improvements on each round So it just you repeat phases, the four phases over and over and over And so you just keep going in a circle. the big bang model typically Good for small prod. a little work being done on planning, and most of the roads sources are for development And with that comes into as you bang you're done you just hit it hard Everybody jumps in all hands on deck and that's the big bang model. but if you're dealing with a small project that is very tiny in nature and that you can do quickly. that would be a really good model to use. The agile model Again this is one of the I use customer interaction and feedback So you're basically reaching out to the product owners getting feedback from them on how the process is going You have a backlog, sprints are usually in two week cycles. And what ends up happening is you'll, you'll go through the backlog you prioritize what you're going to do You do that product. And then at the end of it you the next sprint. anything that is considered a bug that doesn't critical gets thrown back in the backlog and then it gets reprioritized prioritize in the next sprint. it's basically you test it at each iteration. And so there is testing it's put into a testing your production, our staging and production. And so that process is done through the agile model Can it depends on which one works best for you and your organization. So in the past you would test after completion strategy for security And they would typically do this at the end of everything. If and I say that even if the case has many times, they wouldn't even test. but it does leave you vulnerable especially if you're waiting to the end that things have been in production. incorporating security at the beginning does help. Create more secure applications and it reduces your overall risk. Ah, From someone getting access to you And especially during the time when you maybe if you find a mistake, But you know what you fixed. Eight of the 10 but you found two of them that are vulnerable. Well that's good That's I mean at least there's only two versus if you don't add security from the beginning, you now have 10 plus and that causes a lot of issues. you incorporate code review and pen testing and your architecture analysis and there's different SDLC models available Microsoft has a development model. M S S D L and then NIST also talks about it with 800 dash 64 which is a national national national Institute of tech. And this 800 dash 64 does provide security considerations into system development lifecycle. Now there's also another model it's called class which is a comprehensive lightweight application security process class. and this says a set of processes mapped to job roles and allows for early security in stages. So again there's different SDLC models that you have to look at And when it comes to the CISSP they're going to focus on what are some models that are available. And I say when I say that it's going to, it's one of the questions that you could run into doesn't mean that this specific question is on the task No, not saying that at all, but it is a Microsoft development life cycle One question you could potentially see is when considering SDLC models that are available to you. What's one of the following is a model, the model T by Ford, the model. Vega from the car, the model XYZ or the Microsoft security development life cycle model. Or which which a government organization. you with this and that's the NIST 800 dash 64. So those are the questions that you could see on the CISSP exam…Okay That's all I had for the CISSP integration. And now we're going to roll into the CIS is P training eight.one Understand and integrate security in software development life cycle That's the plan We're gonna talk about it in this next objective, As part of the site reduce ever his podcast And there's going to be your CISSP training's going to be available to you. all of the videos that I've created over the time around CISSP are going to be there. The CIS P training manual that's are videos that are focused on the ISA. squared. Exam that are there There's about 129 different, videos that you can watch They'll take you through zero all the way to hero. And the cool part about it is at the end of the day when it's all said and done, it will set you up substantially for to pass the CISSP exam. because it it just really will, you have the knowledge that you get from those videos what you've done on your own. And if you want to go self study for the test you are going to have a subset substantial chance of passing the test. I mean it you'll pass it the first time And that's the ultimate goal is that we want you to help you pass it. The first time. All right so let's roll right into the training. Okay So when we're looking at security again for software environments now this is to all this information I'm providing you is considered out of the ISC square training manuals that have been provided. So what you saw with the original CISSP integration is from InfoSec Institute This is actually out of. My knowledge and working with the also the ISS ISC squared tra official training manual for 2018. Now when you're talking with key aspects you need to avoid developer. even to prevent developers in a work environment from creating an environment that is bad for software. you also need to have the ability to tap apply technical controls where appropriate in your software environment. And it's also important to understand that what could happen if your software development area is compromised. What would somebody get if they got into your code repository? what if they got into your your code and development environment? So what are some key aspects to keep in mind in there? Especially if you're developing apps for your company what kind of credentials could they potentially steal? Did utilize and leverage against you development security considerations You need to have a separate business development functions And this would come into the place where you have email slash document management in a firm should be separate from development. They need to be in separate environments. Not necessarily need to be in separate, completely separate environments but they needed not be work. Your your daily work stuff and your development stuff should be separate. you need to utilize active directory groups and or virtual must. As you're looking at creating, your security environment So those are important things again that separates from the business environment the business network. considered development environment has been compromised So if you look at it from a standpoint of a business are should say most, develop our most networks. You need to consider as you're building out security And as you're looking at what's available to you. The fact that your development environment might be compromised. And that means you just separate your admin and user accounts They can not have the same ability to work on the same things. And you didn't incorporate multifactor as it relates to dealing with security for your environment. it is with your the pin you have like say you go on and you log in you have to enter any multi-factor code. That's on your phone The second token that allows you in, there also would request like multiperson review a good thing is to have someone within your organization review your code before it gets shipped to production. That allows to look for any sort of bugs that may be there. Or something else that may have affected it. also look at trust but verify you need to trust your individuals, but not necessarily their accounts. and that's another thing to consider is that as you are. Dealing with these accounts. Are people, your people are working for you at you need to trust them but their individual network accounts could be compromised and they wouldn't even know it. So it's important that you do trust your people but not there. Your individual accounts. You need to incorporate logging and monitoring which we talked about last week and the importance of doing that. security actions You need to reduce your attack surface And by doing that is that if you have something in production don't have a lot of spurious pages that are sitting out there available for people to go and attack, keep it clean keep it crisp, and you need to protect your assets that your credentials to get into your property It's imperative that you do that secret keys are important as well. And then you also need to understand from an incident response standpoint what is the impact of a compromise and ensure that those controls are in place to limit slash manage the Compromise If it does occur. keep production development environment separate and then ensure again when logging and monitoring isn't is enabled and being monitored. The problem is is turning on logging and monitoring is great but if you don't do anything with it, So much. So it's imperative that you do things like that…Now you're dealing with configuration management as an aspect of secure coding you need to impact the analysis of your change. and you need to request change It needs to be done through the sprint cycle It doesn't mean you go in and just make changes. You should have a sprint cycle set up, whether you're using one of those different waterfall methods and you need to go ahead and put that change in. You also need to have a formal approval process to make that change and put that in the place highly recommended that people are involved in conversations on the phone. And if you have an automated change request process, there needs to be some way to verify that So that if somebody got in a hacker and said Hey add this level of code into your environment please. That would be a bad thing. also approve and reject changes You need to have a formal approach process on how to deal with that. And then ways to test the change, that is in your environment basically a non-production location that you could do through like, you could have it set up on AWS or someplace like that that it has a pipeline where we actually go through and run automated testing. You have that place to check for change. Schedule a time to change the production again come back to when would you do this Have a plan organize orchestrated event, and then document the change Make annotations in the document control. Now you're dealing with versioning. You need to have some level of nomenclature around this You need to have a naming convention and this could come down to some level of late labeling you get your one dot oh your one.one your one dot two so on and so forth And you need to have documentation around your versioning and why you did it. the software configuration management is imperative as it deals with version controls. And the one thing I've learned is that documentation around versioning is definitely a it's an art and and how people do it And then the commenting that goes along with the versioning and labeling. that will cause issues as if you have ineffective version controls, it will cause outages and issues And because what it comes down to is people don't understand. Y you're going from one.one to one.one one one dollar.one one.one one. Yeah I just confused myself. See how easy it is that can happen to anybody. So the point of that is is versioning is important but you needed to have that defined in a written format somewhere. Now your code repositories these are impose very important that you take care of your code repositories. because the fact they keep everything there they act as a central location for developers, your GitHub or Bitbucket your source forge all of those act as a code repository. And so you need to understand the security around that Because again if a hacker gets into those, what's that going to get they're going to get all of your code Well if your code has proprietary information in it, that would be bad. That'll take you out of business Your competitor could get it. And now you're done. you also need to look at a single sign on or multifactor piece to this as well. Avoid the use of API keys in the code repository So the API key basically is set up so that. It will connect to something else and you. API key may have credit is acting as a credential. Well if you have these API keys that are sitting in your code repository, somebody could utilize the API connect into your environment and you wouldn't even know it. unless you have proper logging and monitoring enabled And so odds are high If you have API keys in your codes. You might not have logging and monitoring enabled And then therefore now they're in your environment just like in they're able to pass data in and out without anybody really even seeing it. you need to have security best practices Do avoid remove any sensitive data within the repository and control access by adding removing the, and adding removing process. You also need to have a security.md file which would have your disclosure policies security update policy configurations and gaps and possible enhancements Again that's a message file That's available to talk about security and what could be W what needs to be changed What has been changed? Well how can people disclose it and so forth? You need to rotate your SSH keys and your personal tokens. again those are good best practices Don't keep them the same It's important to move that stuff around. However we do know this people are human and people will if they default to the fact of it's hard to do it they will not do it So something to consider is that many software development companies are many people will not rotate the keys They just won't. And and so therefore you need to look at how do you implement that into your environment? Always consider security when you are developing anything…All right So that's all I have for the CISSP around the ISC square training manual 2018. Let's roll into the CIS. P exam questions. Okay this one's on usernames and passwords. Now considering a development security there are some key considerations you need to be aware of. And I said considering twice considering and considerations those considering. All right So there's some key things that you consider. W a separate business and development functions. Be considered development environment compromised. See trust but verify. D all the above. E none of the above. So when considering development security there are some key considerations you need to be aware of. Separate business development functions. Consider the development environment a compromised. Trust but verify or all the above or none of the above. Answer is B all the above They are all a crucial to thinking around development security. Again separate business environment. You consider your environment compromise you trust but verify you control your. You trust your people but at the same time as you you don't trust their credentials. Those are key things As it relates to username and password in the software development life cycle. Okay this one's on preventative access controls What are the various SDLC development models covered in the CISSP exam? Waterfall. V-shape. Iterative. Agile…spiral and big bang. That was a B. Is waterfall X shaped. Repetitive. Agile. spiral and big bang…See waterfall why shape? He has a lot of letters They're repetitive. Agile. Spiral and big bang. Or D none of the above. So which ones are involved in that are gonna be covered by the CISSP exam. And then now. Number is or the letter is a waterfall V-shaped iterative, agile spiral and the big kahuna bang. All right That's that question right there Again those are important things You need to know the models on the and what are some of the pros and the cons around each of those development models.