|
Establish the Test Target
| Clearly state your test target, which could be a range of IP addresses, one Web application, or a set of Web applications. |
Select Test Environment
| Given the high impact of a security test, it is recommended to run it in a pre-production environment. In the case where
you have to use a production application, you need to run only safe tests that will not destabilize the applications
under test. |
Define Test Scope
Define the security tests that you will run based on the security test policy, your role, and the objectives of the security
test.
|
Determine Test Restrictions
| Talk to all of the stakeholders involved (application owners, developers, and so on) in order to determine all of the test
restrictions. Special consideration should be given to the applications already deployed into a production environment. |
Determine Test Window Details
| Reach agreement with all of the stakeholders on the date and time for running the tests, in order to minimize the overall impact of the
assessment. |
Obtain Access Credentials
| Create a temporary, special account solely for the purpose of security testing. Delete or make sure that the account is
properly disposed of at the end of the test cycle. For role-based access, multiple accounts might be needed. |
Obtain Stakeholder Approval
| Given the potential impact of a security assessment, make sure that all of the stakeholders are informed, and any necessary
approvals have been obtained. |
Obtain Stakeholder Contact Info
| Get all of the contact information that you will need in case of an unexpected event (for example, a crash or a reboot). |
|