Computer security
Training firm ISC2 has launched the Certified Secure Software Lifecycle Professional programme

ISC2 scheme to nurture security skills

CSSLP programme designed to improve the credentials of software developers

Written by Phil Muncaster

Security training provider ISC2 will today launch a new certification programme designed to improve the security credentials of software developers and ultimately raise the standard of applications.

The Certified Secure Software Lifecycle Professional (CSSLP) programme is open to security professionals who can demonstrate four years of professional experience in the software lifecycle process or three years of experience and an IT degree.

"Despite hype in the press about data disclosures, according to Gartner about 80 per cent of breaches are actually caused by badly implemented or insecure software," said ISC2's European managing director John Colley.

"Attacks are now hitting the application and end-user. The security industry is realising that, while it's important to have good policies and processes, if the software has holes in it you're on a hiding to nothing."

From this month until March next year, ISC2 will run an "experience assessment process" which will help to develop an exam question base.

Subject areas covered in the process will be software concepts, requirements, design, implementation and coding, testing and deployment. The first exams will then follow in June 2009.

The organisation expects the certification in time to be as widespread and influential as its CISSP qualification, with senior management using it as part of their criteria to judge new recruits in software development, said Colley.

Graham Titterington of analyst firm Ovum welcomed the standard. "I tend to be sceptical about this type of thing but I feel quite supportive of this one, because they've recognised an area not covered in the traditional academic curriculum," he said.

"There's a lot more interest from the vendor side to improve secure software development too, so it's also timely to address this sort of thing."

Nigel Jones, director of the government-backed Cyber-Security Knowledge Transfer Network, said that commercial pressures and a developer culture focusing too heavily on functionality rather than security had led to poor software development.

"I hope the initiative will generate a body of knowledge that will be shared, because this area needs to be looked at," he said. "Some companies have developed their own lifecycle models but there is not a universal view on this. "

reader comments

related articles

BBCInternet

BBC security glitch causes spam wave

'Administrative error' forwards junk mail to thousands of mailing list subscribers 23 Sep 2008

 

3D Secure uptake soars to 25 million

Apacs claims major milestone for authentication standard 22 Sep 2008

West Midlands Police loses data stick

IPCC to investigate latest in a long line of public sector data losses 16 Sep 2008

Insolvency Service loses laptop

More than 100 records of company directors have gone missing 17 Sep 2008

Security know-how must reach the widest audience

Raj Samani says that if IT systems are to become more robust, users need to be empowered 18 Sep 2008

Infosec: Reputation driving information security

Security is now everyone's problem 23 Apr 2008

McAfee aims to ease NAC woes

Unified Secure Access promises easier deployment and better access controls 20 Oct 2008

Security hits the business agenda

ISC2 survey highlights the growing importance of information security as a business enabler 23 Apr 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Keeping IT in fashion

John Bovill has been hooked on retail since his early years as a fashion market trader. His industry knowledge is now helping him build a slick IT operation, reports Charlotte Moore 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Can brand building reverse a decline in IT graduate numbers?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

StarFeatures

Retaining the stars of IT

Jim Mortleman investigates the innovative techniques IT leaders are using to hang on to their star performers 20 Nov 2008

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Advertisement

Primary Navigation