Summary

In this chapter, we have suggested the setting up of a security-testing knowledge kit to include the testing guides and related security tools. The OWASP Security Knowledge Framework (SKF) provides an in-house security-testing knowledge portal with an OWASP ASVS checklist, security knowledge, and a code example by default. The security team can use the OWASP SKF to further customize the security-testing knowledge portal.

To develop a security-testing plan, we suggested referring to the industry references, such as an OWASP testing guide, a PCI penetration testing guide, a NIST 800-115, and a Mobile Security Testing Guide (MSTG). One typical security-testing plan should include the testing objective, baseline, testing environment, ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.