Fuzz Testing
What is Fuzz Testing?
A software testing technique that provides invalid, unexpected, or random data as input to programs to discover security vulnerabilities and coding errors.
Terms that appear alongside fuzz testing
Each of these is named in at least one of the same controls as fuzz testing. The number is how many controls name both.
- security testing 3 shared controls
- penetration testing 3 shared controls
- dynamic application security testing 2 shared controls
- application security testing 2 shared controls
- application security 2 shared controls
Frameworks that govern fuzz testing
What the standards actually require on fuzz testing
Requirements naming fuzz testing across 3 standards, quoted from the control text.
Test executable software to detect vulnerabilities using dynamic application security testing, fuzz testing, and penetration testing on a defined cadence. Tie test scope to risk and feature changes.
SP800-218-PW.8.1 · Executable Testing for Security →Per OWASP DSOMM Test and Verification dimension: implement comprehensive security testing. Requirements include (a) integrate Static Application Security Testing (SAST) in CI/CD with developer feedback + tuning + (b) operate Dynamic Application Security Testin...
DSOMM-4 · Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing →The vendor must perform security testing throughout development including static analysis, dynamic analysis, fuzz testing, and penetration testing aligned with the software's risk profile.
SSLC-7.1 · Security Testing →Questions people ask about fuzz testing
What is Fuzz Testing?
Why is Fuzz Testing important for compliance?
Which compliance frameworks address Fuzz Testing?
Where can I learn more about Fuzz Testing?
See how Fuzz Testing applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.