There are two kinds of privacy information that need to be protected. One is the sensitive information related to the application security, such as the password, API key, encryption key, CA certificate, and the other one is the Personally Identifiable Information (PII), which is also regulated by GDPR. For the sensitive information review, the functions that relate to IAM, encryption, session management, logging, CA manager, and administration are those modules that directly handle the sensitive information. Here are the general testing guidelines for the privacy data-handling life cycle:
Data life cycle |
Testing key points |
Suggested testing tools |
Transmission of data |
|
SSLyze, NMAP, Wireshark |
Storage of data |
|