Chapter 13. Day 13 – Security Assessment and Testing - Designing, Performing Security Assessment, and Tests
This chapter covers tools, methods, and techniques used for identifying and mitigating risks due to architectural and developmental issues in information assets and associated infrastructure, by systematic security assessment and testing. The requirements pertaining to security controls and measures to assess their continued effectiveness are covered in detail here.
A candidate appearing for a CISSP exam is expected to understand the foundational concepts and possess knowledge of the following key areas of the security assessment and testing domain:
- Security assessment and test strategies
- Security control testing
- Designing and validating assessment and test strategies
- Understanding security testing and tools, methods, and techniques
- Understanding the effectiveness of controls