Please enable JavaScript.
Coggle requires JavaScript to display documents.
Security Assessment and Testing - Domain 6 (Assessment and Testing…
Security Assessment and Testing - Domain 6
Assessment and Testing Strategies
Security Assessment Program
Security Assessment Foundation
need to be well documented and repeatable
assessment tools
code analysis
vuln scanners like nessus
social engineering tools
pen testing tools
web app scanners
program concersn
scope creep
training new employees
competition for staff
strategy
Ensuring objectives have been met.
Validating controls
Identify Issues
Due Diligence
Resource Contraints
Centralized services
important data
Start with critical systems
Security Assessment Types
Audits
Vuln Assessments
Test Coverage Analysis
Pen Testing
Code reviews
Synthetic Transactions
Misuse Testing
DR recovery simulations
BC exercises
Interface Testing