- Develop the test plan: Now that you have testable requirements for the information system and you are in the design phase, it is time to develop the test plan, test procedures, and mechanisms you will use to report the results of the information security test that you perform. Your test plan should answer the following questions:
- What is the scope of the test?
- Who will be conducting the test?
- What is required to conduct the test (tools, personnel, and so on)?
- How should the outputs of the testing be handled (company proprietary, confidential, and so on)?
- If a system outage or a security event occurs, who should be contacted?
Your test procedures should be carefully planned to include all the necessary steps to conduct the ...