The scope of the security checklist we will discuss here is mainly for pre-production deployment releases. The DevOps and the security team do the final testing before the deployment to production. In the best-case scenarios, those defined security checklists can be done automatically. This will help the DevOps team perform regular security checks, even after the deployment to production. Refer to the Further reading section for the reference sources of every tool. The following table shows the feature being checked, the security testing approaches, and the suggested security testing tools:
Security category |
Security testing approaches |
Suggested security testing tools |
Hidden communication ports or channels |
|