Security Testing
What is Security Testing?
The process of evaluating the security of systems, applications, and networks through various testing methodologies to identify vulnerabilities.
Terms that appear alongside security testing
Each of these is named in at least one of the same controls as security testing. The number is how many controls name both.
- application security testing 14 shared controls
- application security 14 shared controls
- information security 13 shared controls
- secure coding 11 shared controls
- penetration testing 10 shared controls
- encryption 10 shared controls
- owasp 9 shared controls
- code review 8 shared controls
Frameworks that govern security testing
What the standards actually require on security testing
Requirements naming security testing across 6 standards, quoted from the control text.
Security Testing. Security testing tools (DAST/IAST) are integrated into the pipeline so applications are tested as they are built.
ST1.4 · Integrate opportunistic security testing into the pipeline →Content filters used by CDSs undergo rigorous security testing to ensure they perform as expected and cannot be bypassed.
ISM-1524 · Content filters used by CDSs undergo rigorous security testing to ensure they perform as e →Integrate dynamic application security testing into the delivery workflow as a gating control, so results can prevent vulnerable builds reaching production.
ASBv3-DS-5 · Integrate dynamic application security testing into DevOps pipeline →Integrate routine static, dynamic, and interactive application security testing throughout the development and deployment lifecycle.
ZTMM-APP-TEST · Applications Pillar: Application Security Testing →Design, scope, execute, and document the testing of executable code (dynamic analysis), and record and triage the discovered issues.
SP800-218-PW.8.2 · Execute Security Testing →Organisation regularly tests and monitors the effectiveness of security safeguards protecting personal information.
PMF-SP.3 · Security Testing and Monitoring →Questions people ask about security testing
What is Security Testing?
Why is Security Testing important for compliance?
Which compliance frameworks address Security Testing?
Where can I learn more about Security Testing?
See how Security Testing applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.