CSSLP Study Guide
คู่มือนี้ช่วยผู้สมัครสอบ Certified Secure Software Lifecycle Professional (CSSLP) ทบทวน security ตลอด Software Development Lifecycle (SDLC) ผ่าน 8 Domains ตามลำดับใน CSSLP Certification Exam Outline เนื้อหาเขียนเป็นภาษาไทย และคงคำศัพท์ภาษาอังกฤษที่ใช้ในงานและข้อสอบ
[!IMPORTANT] คู่มือนี้จัดทำขึ้นเองเพื่อการศึกษา ไม่ใช่ official ISC2 material ไม่ได้รับ การรับรองจาก ISC2 และไม่มี exam dump ข้อฝึกทั้งหมดเป็นคำถามที่สร้างขึ้นเพื่อ ทบทวนแนวคิด ไม่ใช่ข้อสอบจริง
Exam outline ที่คู่มือนี้ใช้
Section titled “Exam outline ที่คู่มือนี้ใช้”ลำดับ Domain อ้างอิงหน้า CSSLP Certification Exam Outline ของ ISC2 ซึ่งตรวจสอบเมื่อวันที่ 19 กรกฎาคม 2026 หน้าเว็บระบุ effective date เป็น 15 กันยายน 2023
| บท | Official domain | น้ำหนักเฉลี่ย | Objectives | คู่มือ |
|---|---|---|---|---|
| 1 | Secure Software Concepts | 12% | 1.1–1.2 | อ่านบทที่ 1 |
| 2 | Secure Software Lifecycle Management | 11% | 2.1–2.9 | อ่านบทที่ 2 |
| 3 | Secure Software Requirements | 13% | 3.1–3.8 | อ่านบทที่ 3 |
| 4 | Secure Software Architecture and Design | 15% | 4.1–4.7 | อ่านบทที่ 4 |
| 5 | Secure Software Implementation | 14% | 5.1–5.6 | อ่านบทที่ 5 |
| 6 | Secure Software Testing | 14% | 6.1–6.8 | อ่านบทที่ 6 |
| 7 | Secure Software Deployment, Operations, Maintenance | 11% | 7.1–7.13 | อ่านบทที่ 7 |
| 8 | Secure Software Supply Chain | 10% | 8.1–8.5 | อ่านบทที่ 8 |
น้ำหนักเป็นค่าเฉลี่ยตาม outline และรวมเป็น 100% ใช้ช่วยวางแผนเวลาได้ แต่ไม่ควร ละเลย Domain น้ำหนักน้อย เพราะข้อสอบอาจประเมินการเชื่อมการตัดสินใจข้าม SDLC
สารบัญแบบมีคำอธิบาย
Section titled “สารบัญแบบมีคำอธิบาย”แต่ละบทมี learning-objective mapping, แนวคิดเชิงลึก, threats/risks, controls พร้อมเหตุผล, diagrams, pseudo code, case study, exam tips, pitfalls และข้อฝึก พร้อมเฉลย หัวข้อต่อไปนี้สรุปสิ่งที่ควรได้จากแต่ละบท
บทที่ 1: Secure Software Concepts
Section titled “บทที่ 1: Secure Software Concepts”วางฐาน CIA, identity and access, accountability, nonrepudiation, GRC และ classic security design principles เพื่อใช้ภาษาเดียวกันตลอดคู่มือ
เริ่มบทที่ 1 — Secure Software Concepts
บทที่ 2: Secure Software Lifecycle Management
Section titled “บทที่ 2: Secure Software Lifecycle Management”นำหลัก security เข้า development methodology, standards, roadmap, control gates, documentation, metrics, reporting, risk management, operational governance และการ decommission application อย่างเป็นระบบ
อ่านบทที่ 2 — Secure Software Lifecycle Management
บทที่ 3: Secure Software Requirements
Section titled “บทที่ 3: Secure Software Requirements”เปลี่ยน business, compliance, data, privacy, access และ abuse concerns ให้เป็น requirements ที่ testable และ traceable รวมถึง Security Requirements Traceability Matrix (SRTM) และ third-party requirements
อ่านบทที่ 3 — Secure Software Requirements
บทที่ 4: Secure Software Architecture and Design
Section titled “บทที่ 4: Secure Software Architecture and Design”แปลง requirements เป็น security architecture, interfaces, technology choices, threat models, risk reviews, non-functional properties และ operational topology ที่มีเหตุผลและหลักฐานตรวจสอบได้
อ่านบทที่ 4 — Secure Software Architecture and Design
บทที่ 5: Secure Software Implementation
Section titled “บทที่ 5: Secure Software Implementation”ลงรายละเอียด secure coding, code analysis, controls, component integration, risk treatment และ secure build ตั้งแต่ validation และ concurrency ไปจนถึง compiler warnings และ artifact protection
อ่านบทที่ 5 — Secure Software Implementation
บทที่ 6: Secure Software Testing
Section titled “บทที่ 6: Secure Software Testing”ออกแบบ risk-based testing strategy และ test evidence ผ่าน DAST, IAST, penetration testing, fuzzing, failure testing, V&V, defect tracking และการ ปกป้อง test environment/data
อ่านบทที่ 6 — Secure Software Testing
บทที่ 7: Secure Software Deployment, Operations, Maintenance
Section titled “บทที่ 7: Secure Software Deployment, Operations, Maintenance”ติดตาม signed artifact ผ่าน release, installation, approval, monitoring, incident response, patch/vulnerability management, runtime protection, continuity และ SLO/SLA ใน production
อ่านบทที่ 7 — Secure Software Deployment, Operations, Maintenance
บทที่ 8: Secure Software Supply Chain
Section titled “บทที่ 8: Secure Software Supply Chain”ปิดวงจรด้วย component inventory/SBOM, supplier assessment, pedigree, provenance, secure repositories/builds, acquisition requirements และ contractual protections ตลอดอายุ dependency
อ่านบทที่ 8 — Secure Software Supply Chain
เส้นทางการอ่านที่แนะนำ
Section titled “เส้นทางการอ่านที่แนะนำ”การอ่านตามลำดับ 1–8 ให้บริบทครบที่สุด เพราะแต่ละบทส่งต่อคำศัพท์ หลักฐานและ decision boundaries ไปยังบทถัดไป หากมีเวลาจำกัด ให้เลือกเส้นทางตามจุดอ่อนแล้ว ย้อนกลับบทต้นทางเมื่อเจอ cross-reference
- อ่านรอบแรก: อ่านบทนำ, objective mapping, diagrams และสรุปบททั้ง 8 บท
- อ่านรอบลึก: ศึกษา models, threats, controls, trade-offs และ case study
- ฝึกเหตุผล: ทำข้อฝึกก่อนเปิดเฉลย แล้วอธิบายว่าเหตุใดตัวเลือกอื่นจึงด้อยกว่า
- ทบทวนข้ามบท: ตาม traceability จาก requirement → design → code → test → release/monitoring → supplier evidence
- ปิดช่องว่าง: กลับไปอ่าน exam tips และ common pitfalls ของ Domain ที่ตอบผิด
แผนที่การไหลของหลักฐานตลอด SDLC
Section titled “แผนที่การไหลของหลักฐานตลอด SDLC”ภาพนี้สรุปความสัมพันธ์หลักที่คู่มือใช้ซ้ำ การไหลเป็นวงจรเพราะข้อมูลจาก testing, operations และ supply chain ต้องย้อนกลับไปแก้ governance และ requirements
ลูกศรไปข้างหน้าแสดงการเปลี่ยน intent เป็น evidence ส่วนลูกศรย้อนกลับแสดง feedback ที่ทำให้ risk decisions และ controls ปรับตามข้อมูลจริง
วิธีใช้ข้อฝึกอย่างมีประสิทธิภาพ
Section titled “วิธีใช้ข้อฝึกอย่างมีประสิทธิภาพ”ข้อฝึกวัดการแยก role, lifecycle phase, evidence และ risk decision มากกว่าการจำ คำศัพท์เดี่ยว ใช้กระบวนการต่อไปนี้ทุกครั้งที่ทำคำถาม
- ระบุ asset, threat, vulnerability และ decision owner จากโจทย์
- ระบุว่าโจทย์อยู่ lifecycle phase และ Domain ใด
- แยกว่าโจทย์ถาม preventive action, detection, evidence หรือ risk acceptance
- ตัดตัวเลือกที่แก้คนละ phase หรือให้ผู้ไม่มีอำนาจยอมรับ residual risk
- เลือกคำตอบที่ตรง requirement และลด risk ด้วยหลักฐานที่ตรวจสอบได้มากที่สุด
- อ่านเฉลยแม้ตอบถูก เพื่อเทียบเหตุผลและทบทวน common pitfall
ขอบเขตการใช้งาน
Section titled “ขอบเขตการใช้งาน”คู่มือนี้เป็นฐานทบทวน ไม่แทนการตรวจ primary source สำหรับกฎหมาย มาตรฐาน
framework version หรือข้อมูลการสอบที่อาจเปลี่ยนแปลง ก่อนสมัครสอบให้ตรวจหน้า
ISC2 โดยตรงอีกครั้ง และใช้ [uncertain] ในการจดโน้ตส่วนตัวเมื่อข้อมูลขึ้นกับ
เวลา เขตอำนาจ หรือ version ที่ยังไม่ได้ยืนยัน