We have discussed web security testing and also privacy. The security testing must tie in closely to the business and the target of the application, which will be related to not only the testing scenario but also to the testing tools. Understanding the application domain knowledge is always the first step to plan the security testing. Here is a summary of industry references for each security testing domain. An organization may further develop its own domain-specific testing plan based on these references. Take a look at this table:
Security domain |
Industry Security Best Practices and Testing Guide |
Web security testing |
|
Virtualization security testing |
|