From the course: Certificate of Cloud Security Knowledge (CCSK) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Secure design and architecture
From the course: Certificate of Cloud Security Knowledge (CCSK) Cert Prep
Secure design and architecture
- [Instructor] The application security domain for the CCSK exam will have six questions. It's important to note that application security challenges that existed pre-cloud continue in the cloud, and applications still are a leading attack surface inside of the cloud. The cloud security alliance defines five stages in their version of the secure software development lifecycle. While the CCSK doesn't order the application security domain employing their SSDLC, it's how I will address it, since it makes it very easy to absorb. We will begin with the secure design and architecture. In the secure design and architecture, choosing an architectural approach should always proceed the design. Architecture is an abstract representation of technology design, which is the implementation of the tools and approaches of the architecture. A secure architecture should specify an enterprise wide approach to software development, incorporating services, components, tools and resources. This should…