(ISC2) announced preparations for a new certification designed to validate secure software development practices and expertise to address the increasing number of application vulnerabilities.

The Certified Secure Software Lifecycle Professional (CSSLP) aims to stem the proliferation of security vulnerabilities resulting from insufficient development processes by establishing best practices and validating an individual's competency in addressing security issues throughout the software lifecycle (SLC). It takes a holistic approach to software security.
Code-language neutral, it will be applicable to anyone involved in the SLC, including analysts, developers, software engineers, software architects, project managers, software quality assurance testers and programmers.
Subject areas covered by the CSSLP exam will include the software lifecycle, vulnerabilities, risk, information security fundamentals and compliance. Candidates must demonstrate four years of professional experience in the SLC process or three years of experience and a bachelor's degree (or regional equivalent) in an IT discipline.
The seven domains of the CSSLP CBK, a compendium of secure software topics, are:
- Secure Software Concepts
- Secure Software Requirements
- Secure Software Design
- Secure Software Implementation/Coding
- Secure Software Testing
- Software Acceptance
- Software Deployment, Operations, Maintenance and Disposal
The first CSSLP exam is scheduled for the end of June in 2009. Currently, (ISC)² is seeking qualified professionals who meet experience and other requirements to participate in the assessment. They will become the first CSSLP holders and be asked to contribute to the exam development process and assist in other program development tasks. Applications for the CSSLP experience assessment will be accepted from Sept. 25, 2008 through March 31, 2009, with the first education seminars slated for Q1 2009.
CLick on Read Me... below to get more details -->
Here is the info posted at:
https://www.isc2.org/cgi-bin/content.cgi?category=1691
It's time we addressed the problem.
Join our elite membership as among the first to become certified as a Certified Secure Software Lifecycle Professional (CSSLPCM).
We all know what the problem is. We see it on the news, read about it online, and hear how our colleagues have to face it. Now, (ISC)² has the solution and you can get it before the first exam is available.
If you have 4 recent years of professional experience in the area of the Software Development Lifecycle (SDLC) and are an expert in 4 of the 7 CSSLP Experience Assessment topic areas, you need to get this industry that will lead the industry by establishing standards and instilling best practices.
For a limited time, CSSLP certifications will be offered to candidates who submit qualified "Accomplishment Records" which are self-reported descriptions of experience relevant to 4 of the 7 topic areas. If not approved, you will be able to sit for the exam at no additional charge.
- Experience Assessment Window:
September 30, 2008 - March 31, 2009
- Official (ISC)² Education Seminars begin early 2009.
- Exams start June 2009
Start here:
Have questions? Read more about CSSLP here
CSSLP Online Experience Assessment steps to certification
- Complete the application form with your payment information.
- Upload your current resume or Curriculum Vitae where requested. This must contain: dates of employment, job titles and a brief description of your duties
- Copy and Paste (4) essay responses where requested as described in the Experience Assessment Essay section.
- Submit the completed registration form by clicking the "Register" button at the end of this registration form.
CSSLP Experience Assessment Topic Areas
- Applying Security Concepts To Software Development
- Software Requirements
- Software Design
- Software Implementation / Coding
- Software Testing
- Software Acceptance
- Deployment, Operations, Maintenance And Disposal
CSSLP candidate requirements
- Submit the Experience Assessment application form with your payment information
- Have a minimum of four years recent experience in four or more of the 7 CSSLP Experience Assessment Topic Areas.
- Successfully complete the endorsement process
- Attest to the truth of his or her assertions regarding professional experience, and legally commit to abide by the (ISC)² Code of Ethics
- Successfully answer four questions regarding criminal history and related background
Experience Assessment Essay Section
Applicant must compose four essay responses addressing the topics listed below.
Qualification decisions will be based on how your experience relates to subjects listed below. When composing your essays, please address and provide documentation describing your expertise as it relates to the topics identified below.
Each essay response must be no more than 500 words and no less than 250 words. All essays must be in English.
The title of your essay should be the topic you are addressing in the essay (listed below).
Topic Areas:
- Applying Security concepts to Software Development
- Software Requirements
- Software Design
- Software Implementation/Coding
- Software Testing
- Software Acceptance
- Deployment, Operations, Maintenance and Disposal