An overview of security assessment and testing
Risk management involves assessment and testing pertaining to security. Controls such as preventive, detective, or corrective measures require appropriate design and implementation. During the design, development, implementation, and operational phases of security controls, assessment and testing need to be performed on periodical basis to ascertain the effectiveness of security controls and their continued suitability for protecting the assets.
Generally, security assessment and testing is carried out on the basis of suitably designed assessment and test strategies. Such strategies include the application of suitable testing tools, methods, and techniques. It is also important that the outcome of the test results provide the data pertaining to the effectiveness of the implemented security control.
Observe the following illustration. IT assets, such as computers, contain operating systems, databases, and applications. They are used in business...