StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 8: Software development security

Security in the SDLC: waterfall, agile, DevOps, DevSecOps, scaled agile

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

The software development lifecycle (SDLC) is the structured process for creating software, from idea to retirement. Its phases are commonly described as initiation and requirements, design, development (coding), testing, deployment and implementation, operations and maintenance, and disposal. The central security lesson is that security must be built in from the start, because fixing flaws late in the lifecycle is far more expensive and less effective than preventing them. A design flaw found in production can require rearchitecting; the same flaw found in a design review costs a meeting.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan