Chapter 10. Security-Testing Plan and Practices
We have already discussed the security practices involved in development, which included phases such as securing architecture, securing design, threat modeling, and securing coding. We will now discuss the security-testing plan and practices in the testing phase.
The objective of this chapter is to give an overview of what a security-testing plan, security-testing domains, and the minimum set of security-testing scope. We will discuss a security testing plan, testing approaches, risk analysis, security domains, and industry practices, to build your security-testing knowledge base. In addition, we will introduce some industry best practices, testing approaches, and security tools, for security testing.
We will cover the following topics in this chapter:
- Security-testing knowledge kit
- Security-testing plan templates
- Web security testing
- Privacy
- Security-testing domains
- Thinking like a hacker
- Security-training environment