Security assessment and test strategies
Information technology infrastructure consists of heterogeneous combinations of software, hardware, networking, and communication-related assets. Such a combination is used in design, development, production, and business operations. Risk assessments on IT infrastructure provide an area of risk on the assets and the impact to business that it would have if the assessed risk materializes. However, risk is a function of probability and consequence. Hence, both the probability and consequence of a risk to business needs to be adequately ascertained in order to design suitable security controls. Such controls have to be effective in mitigating the risk. In this context, proper security assessments and test strategies are required to ascertain the suitability of controls to mitigate the assessed risk, and their continued effectiveness if the risk value changes.
Security assessment and test strategies are administrative controls that provide processes and...