Chapter 6. Security Assessment and Testing
This chapter covers the following topics:
Assessment and Testing Strategies: Explains the use of assessment and testing strategies.
Security Control Testing: Concepts discussed include the security control testing process, including vulnerability assessments, penetration tests, log reviews, synthetic transactions, code review and testing, misuse case testing, test coverage analysis, and interface testing.
Collect Security Process Data: Concepts discussed include NIST SP 800-137, account management,
Get CISSP Cert Guide, Second Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.