Task Descriptor: Refine Security Test Plan
This task describes the main steps for developing a security test plan. All or some of these steps can be performed when you start from scratch, or when you just refine an existent test plan.
Based on Method Task: Develop Security Test Plan
Relationships
InputsMandatory: Optional:
  • None
External:
  • None
Steps
Establish the Test Target
Clearly state your test target, which could be a range of IP addresses, one Web application, or a set of Web applications.
Select Test Environment
Given the high impact of a security test, it is recommended to run it in a pre-production environment. In the case where you have to use a production application, you need to run only safe tests that will not destabilize the applications under test.
Define Test Scope

Define the security tests that you will run based on the security test policy, your role, and the objectives of the security test.

Determine Test Restrictions
Talk to all of the stakeholders involved (application owners, developers, and so on) in order to determine all of the test restrictions. Special consideration should be given to the applications already deployed into a production environment.
Determine Test Window Details
Reach agreement with all of the stakeholders on the date and time for running the tests, in order to minimize the overall impact of the assessment.
Obtain Access Credentials
Create a temporary, special account solely for the purpose of security testing. Delete or make sure that the account is properly disposed of at the end of the test cycle. For role-based access, multiple accounts might be needed.
Obtain Stakeholder Approval
Given the potential impact of a security assessment, make sure that all of the stakeholders are informed, and any necessary approvals have been obtained.
Obtain Stakeholder Contact Info
Get all of the contact information that you will need in case of an unexpected event (for example, a crash or a reboot).
Properties
Predecessor
Multiple Occurrences
Event Driven
Ongoing
Optional
Planned
Repeatable