Skip to content

CSSLP Study Guide

คู่มือนี้ช่วยผู้สมัครสอบ Certified Secure Software Lifecycle Professional (CSSLP) ทบทวน security ตลอด Software Development Lifecycle (SDLC) ผ่าน 8 Domains ตามลำดับใน CSSLP Certification Exam Outline เนื้อหาเขียนเป็นภาษาไทย และคงคำศัพท์ภาษาอังกฤษที่ใช้ในงานและข้อสอบ

[!IMPORTANT] คู่มือนี้จัดทำขึ้นเองเพื่อการศึกษา ไม่ใช่ official ISC2 material ไม่ได้รับ การรับรองจาก ISC2 และไม่มี exam dump ข้อฝึกทั้งหมดเป็นคำถามที่สร้างขึ้นเพื่อ ทบทวนแนวคิด ไม่ใช่ข้อสอบจริง

Exam outline ที่คู่มือนี้ใช้

Section titled “Exam outline ที่คู่มือนี้ใช้”

ลำดับ Domain อ้างอิงหน้า CSSLP Certification Exam Outline ของ ISC2 ซึ่งตรวจสอบเมื่อวันที่ 19 กรกฎาคม 2026 หน้าเว็บระบุ effective date เป็น 15 กันยายน 2023

บทOfficial domainน้ำหนักเฉลี่ยObjectivesคู่มือ
1Secure Software Concepts12%1.1–1.2อ่านบทที่ 1
2Secure Software Lifecycle Management11%2.1–2.9อ่านบทที่ 2
3Secure Software Requirements13%3.1–3.8อ่านบทที่ 3
4Secure Software Architecture and Design15%4.1–4.7อ่านบทที่ 4
5Secure Software Implementation14%5.1–5.6อ่านบทที่ 5
6Secure Software Testing14%6.1–6.8อ่านบทที่ 6
7Secure Software Deployment, Operations, Maintenance11%7.1–7.13อ่านบทที่ 7
8Secure Software Supply Chain10%8.1–8.5อ่านบทที่ 8

น้ำหนักเป็นค่าเฉลี่ยตาม outline และรวมเป็น 100% ใช้ช่วยวางแผนเวลาได้ แต่ไม่ควร ละเลย Domain น้ำหนักน้อย เพราะข้อสอบอาจประเมินการเชื่อมการตัดสินใจข้าม SDLC

สารบัญแบบมีคำอธิบาย

Section titled “สารบัญแบบมีคำอธิบาย”

แต่ละบทมี learning-objective mapping, แนวคิดเชิงลึก, threats/risks, controls พร้อมเหตุผล, diagrams, pseudo code, case study, exam tips, pitfalls และข้อฝึก พร้อมเฉลย หัวข้อต่อไปนี้สรุปสิ่งที่ควรได้จากแต่ละบท

บทที่ 1: Secure Software Concepts

Section titled “บทที่ 1: Secure Software Concepts”

วางฐาน CIA, identity and access, accountability, nonrepudiation, GRC และ classic security design principles เพื่อใช้ภาษาเดียวกันตลอดคู่มือ

เริ่มบทที่ 1 — Secure Software Concepts

บทที่ 2: Secure Software Lifecycle Management

Section titled “บทที่ 2: Secure Software Lifecycle Management”

นำหลัก security เข้า development methodology, standards, roadmap, control gates, documentation, metrics, reporting, risk management, operational governance และการ decommission application อย่างเป็นระบบ

อ่านบทที่ 2 — Secure Software Lifecycle Management

บทที่ 3: Secure Software Requirements

Section titled “บทที่ 3: Secure Software Requirements”

เปลี่ยน business, compliance, data, privacy, access และ abuse concerns ให้เป็น requirements ที่ testable และ traceable รวมถึง Security Requirements Traceability Matrix (SRTM) และ third-party requirements

อ่านบทที่ 3 — Secure Software Requirements

บทที่ 4: Secure Software Architecture and Design

Section titled “บทที่ 4: Secure Software Architecture and Design”

แปลง requirements เป็น security architecture, interfaces, technology choices, threat models, risk reviews, non-functional properties และ operational topology ที่มีเหตุผลและหลักฐานตรวจสอบได้

อ่านบทที่ 4 — Secure Software Architecture and Design

บทที่ 5: Secure Software Implementation

Section titled “บทที่ 5: Secure Software Implementation”

ลงรายละเอียด secure coding, code analysis, controls, component integration, risk treatment และ secure build ตั้งแต่ validation และ concurrency ไปจนถึง compiler warnings และ artifact protection

อ่านบทที่ 5 — Secure Software Implementation

บทที่ 6: Secure Software Testing

Section titled “บทที่ 6: Secure Software Testing”

ออกแบบ risk-based testing strategy และ test evidence ผ่าน DAST, IAST, penetration testing, fuzzing, failure testing, V&V, defect tracking และการ ปกป้อง test environment/data

อ่านบทที่ 6 — Secure Software Testing

บทที่ 7: Secure Software Deployment, Operations, Maintenance

Section titled “บทที่ 7: Secure Software Deployment, Operations, Maintenance”

ติดตาม signed artifact ผ่าน release, installation, approval, monitoring, incident response, patch/vulnerability management, runtime protection, continuity และ SLO/SLA ใน production

อ่านบทที่ 7 — Secure Software Deployment, Operations, Maintenance

บทที่ 8: Secure Software Supply Chain

Section titled “บทที่ 8: Secure Software Supply Chain”

ปิดวงจรด้วย component inventory/SBOM, supplier assessment, pedigree, provenance, secure repositories/builds, acquisition requirements และ contractual protections ตลอดอายุ dependency

อ่านบทที่ 8 — Secure Software Supply Chain

เส้นทางการอ่านที่แนะนำ

Section titled “เส้นทางการอ่านที่แนะนำ”

การอ่านตามลำดับ 1–8 ให้บริบทครบที่สุด เพราะแต่ละบทส่งต่อคำศัพท์ หลักฐานและ decision boundaries ไปยังบทถัดไป หากมีเวลาจำกัด ให้เลือกเส้นทางตามจุดอ่อนแล้ว ย้อนกลับบทต้นทางเมื่อเจอ cross-reference

  • อ่านรอบแรก: อ่านบทนำ, objective mapping, diagrams และสรุปบททั้ง 8 บท
  • อ่านรอบลึก: ศึกษา models, threats, controls, trade-offs และ case study
  • ฝึกเหตุผล: ทำข้อฝึกก่อนเปิดเฉลย แล้วอธิบายว่าเหตุใดตัวเลือกอื่นจึงด้อยกว่า
  • ทบทวนข้ามบท: ตาม traceability จาก requirement → design → code → test → release/monitoring → supplier evidence
  • ปิดช่องว่าง: กลับไปอ่าน exam tips และ common pitfalls ของ Domain ที่ตอบผิด

แผนที่การไหลของหลักฐานตลอด SDLC

Section titled “แผนที่การไหลของหลักฐานตลอด SDLC”

ภาพนี้สรุปความสัมพันธ์หลักที่คู่มือใช้ซ้ำ การไหลเป็นวงจรเพราะข้อมูลจาก testing, operations และ supply chain ต้องย้อนกลับไปแก้ governance และ requirements

findings and evidence

telemetry and incidents

supplier and component risk

1 Concepts

2 Lifecycle management

3 Requirements

4 Architecture and design

5 Implementation

6 Testing

7 Deployment and operations

8 Supply chain

ลูกศรไปข้างหน้าแสดงการเปลี่ยน intent เป็น evidence ส่วนลูกศรย้อนกลับแสดง feedback ที่ทำให้ risk decisions และ controls ปรับตามข้อมูลจริง

วิธีใช้ข้อฝึกอย่างมีประสิทธิภาพ

Section titled “วิธีใช้ข้อฝึกอย่างมีประสิทธิภาพ”

ข้อฝึกวัดการแยก role, lifecycle phase, evidence และ risk decision มากกว่าการจำ คำศัพท์เดี่ยว ใช้กระบวนการต่อไปนี้ทุกครั้งที่ทำคำถาม

  1. ระบุ asset, threat, vulnerability และ decision owner จากโจทย์
  2. ระบุว่าโจทย์อยู่ lifecycle phase และ Domain ใด
  3. แยกว่าโจทย์ถาม preventive action, detection, evidence หรือ risk acceptance
  4. ตัดตัวเลือกที่แก้คนละ phase หรือให้ผู้ไม่มีอำนาจยอมรับ residual risk
  5. เลือกคำตอบที่ตรง requirement และลด risk ด้วยหลักฐานที่ตรวจสอบได้มากที่สุด
  6. อ่านเฉลยแม้ตอบถูก เพื่อเทียบเหตุผลและทบทวน common pitfall

ขอบเขตการใช้งาน

Section titled “ขอบเขตการใช้งาน”

คู่มือนี้เป็นฐานทบทวน ไม่แทนการตรวจ primary source สำหรับกฎหมาย มาตรฐาน framework version หรือข้อมูลการสอบที่อาจเปลี่ยนแปลง ก่อนสมัครสอบให้ตรวจหน้า ISC2 โดยตรงอีกครั้ง และใช้ [uncertain] ในการจดโน้ตส่วนตัวเมื่อข้อมูลขึ้นกับ เวลา เขตอำนาจ หรือ version ที่ยังไม่ได้ยืนยัน