Application Security is a hot topic and increasingly software testers are being asked to carry out “security tests”; sometimes this is in addition to external security tests but often instead of. Despite the widespread availability of resources on security testing, much of it focuses on techniques so it can be difficult for testers to know where to start and what is important to their context.
Building a Threat Model can help testers formulate a more context driven approach to security testing and help frame these tests by linking your application/assets to possible threats and vulnerabilities, to the tests you are carrying out (or not) and the techniques needed to implement them.
MoTaCon is coming, have you got your ticket yet?
Explore MoT
What I learned about influence by becoming a stakeholder
Mitigate security risks by building simple security testing techniques into your daily routine
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community
Comments