From the course: ISC2 Information Systems Security Engineering Professional (ISSEP) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Acquisition/development

Acquisition/development

- [Brad] Welcome back to Cybrary's ISSEP course. I'm your instructor, Brad Rhodes. Let's jump into the next phase of the system development lifecycle. That's acquisition/development. So, in this learning objective, we are going to cover the security activities. We're again going to look at linkages. And we're going to talk about what acquisition/development is. So our security activities here, when we talk about the acquisition or development process, is we're going to do our risk assessment. So we've talked previously, in the risk management ISSEP domain, about what we do in risk assessments. We're going to look at those security requirements that have come out of phase one. We are going to potentially perform functional and security testing, where we're taking the things that we're going to reuse, right? Maybe things like GOTS, Government off-the-shelf, that already exists that we can grab. We're going to test those. We're going to make sure they're going to work for us. And then…

Contents