System testing
Execute the test plan: Now that the system has been fully implemented, this is where the information security professional performs the formal assessment of the information security controls that have been implemented for the information system. The testing that is included in this phase can utilize many tools and techniques to ascertain that the confidentiality, integrity, and availability of the information system is appropriately protected, commensurate with the value of the data contained within it.
The testing included in this phase will examine the operational, management, and technical control of the information system. From a technical perspective, the tester will be able to utilize security specific tools to conduct ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access