We have already discussed the security practices involved in development, which included phases such as securing architecture, securing design, threat modeling, and securing coding. We will now discuss the security-testing plan and practices in the testing phase.
The objective of this chapter is to give an overview of what a security-testing plan, security-testing domains, and the minimum set of security-testing scope. We will discuss a security testing plan, testing approaches, risk analysis, security domains, and industry practices, to build your security-testing knowledge base. In addition, we will introduce some industry best practices, testing approaches, and security tools, for security testing.
We will cover the following topics in this chapter:
- Security-testing knowledge kit
- Security-testing plan templates
- Web security testing
- Privacy...