This lesson covers risks and controls and focuses on the following risks in design: • Code reuse • Flaws vs. bugs o Flaw: inherent fault with the design of a code o Bug: implementation fault • Open vs. closed design Also discussed is controls evaluation: • Efficacy of controls • Economy of mechanism • Cost/benefit analysis • Psychological acceptability

ISC2 Certified Secure Software Life-cycle Professional (CSSLP)

This course helps professionals in the industry build their credentials to advance within their organization, allowing them to learn valuable managerial skills as well as how to apply the best practices to keep organizations systems running well.

Kelly Handerhan
Senior Instructor