top of page
71OMr0D4FrL._SL1500_.jpg
119159849_10158061653118813_5314694876572739015_n.jpg
71eSH5cSYiL._SL1377_.jpg
final.png

CISSP Study Plan – Day 4 of 55 | Systems Development Security & Covert Channels


"SDLC - security must be in all stages, especially the first one. Think like a manager means do your best to mention security and reduce attack surface using threat modeling, but also smart enough to know vulnerabilities will exist after software deployment. Keep going brother !! What a legacy you’re leaving behind before your name has the letters “CISSP” after it." - Luke Ahmed



Today is Day 4 of Yihenew’s CISSP study plan, focusing on systems development security with an emphasis on covert channels and time-of-use (TOU) vulnerabilities.

Using Luke Ahmed’s Study Notes and Theory CISSP course and How to Think Like a Manager for the CISSP Exam, Yihenew explored:

  • Systems Development Security — integrating security controls into the software lifecycle to prevent vulnerabilities from the start.

  • Covert Timing Channels — exploiting the timing of events to pass unauthorized information between processes.

  • Covert Storage Channels — using shared storage or variables in unintended ways to communicate without authorization.

  • TOU (Time of Use) Flaws — when the state of a resource changes between the time it is checked and the time it is used, potentially allowing exploitation.

In this CISSP study plan session, Yihenew learned that understanding these concepts is crucial for identifying security weaknesses that may not be obvious in traditional testing but can be exploited in real-world attacks.

If you’re building your own CISSP exam preparation plan, these topics are critical for mastering both Systems Development Security and Security Engineering domains.d where they sit in the network—is essential for both Communication and Network Security and Security Operations domains.


Follow his full journey on TikTok or check out Day 5.


Yihenew's Resources in the Video:


Course


Practice Questions

 
 
  • Youtube
  • Instagram
  • Linkedin
  • Facebook
  • TikTok
bottom of page