Planning the test
After some workshops with your client and gaining more information about the target system, you should have identified the following:
- The crown jewels and their security functions
- The testing scenarios and questions (and validated them with your client)
- Identified a global "difficulty level" for your scenarios (depending on the "box color", you may already know if a certain component or security function is more or less well-protected)
Now, the question is, How do we allocate time to which scenario? This is a difficult question, especially when you're utilizing a black box approach (since you have no details about the system architecture). Let's talk more about this balancing act.
Balancing your scenarios
Typically, your scenarios will have an associated impact and difficulty. Let's be realistic: at this point, these impacts and difficulties are mainly "gut feelings" since we haven't done...