December 2017
Beginner
330 pages
9h 1m
English
The following diagram provides an example of the security testing responsibilities that the information security professional is responsible for in their organization. This diagram is still a very high-level representation of the potential testing possibilities that can occur throughout the SDLC of an information system.
It is important to note that you must ensure a very delicate balance between testing and improving security on one side, and encumbering your program teams and having them avoid you on the other.
Here are some best practices that I have encountered to ensure success throughout the SDLC regarding information security testing:
Read now
Unlock full access