From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Grouping your tests
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Grouping your tests
- [Instructor] As you plan to execute your security test, you can take advantage of efficiencies if you divide those tests into logical groups. You should consider grouping your test into two groups: functional and non-functional. As a quick reminder, functional test focus on the user experience. They validate that the app does what the user expects it to do. Non-functional tests are designed with an attacker in mind. They focus on what the app was not designed to do. When we first discussed functional tests, I emphasized that security tests don't often fall into this category. That said, functional tests that focus on business logic are the exception to that rule. Business logic and user experience go hand in hand, and an app that fails business logic test would not only make for a bad user experience, but it would also likely contain weaknesses that an attacker might be able to exploit. When we discussed ensuring a comprehensive approach to your testing, we discussed regression test…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)