The scope of infrastructure security testing covers the known vulnerable components inspection, secure configurations, and secure communication protocols. In addition to the uses of tools, the industry organization best practices, including CIS benchmarks, STIG, and OpenSCAP are also introduced.
Infrastructure security
What's the scope of infrastructure security testing?
The following describes the scope of infrastructure security testing:
Infrastructure/platform security | Description | Open source tools and resources |
Known vulnerable components | The known vulnerable (CVE) component is one of OWASP top 10 threats. If one component is exploited, the application can be vulnerable to remote injection or data leakage security... |