Course Summary
The ISTQB Security Tester (CT-SEC) certification focuses on planning, performing, and evaluating security tests from multiple perspectives including risk, requirements, vulnerability, and human factors. It also covers security testing tools and standards.
• Plan, perform and evaluate security tests from a variety of perspectives – policy-based, risk-based, standards-based, requirements-based and vulnerability-based.
• Align security test activities with project lifecycle activities.
• Analyze the effective use of risk assessment techniques in a given situation to identify current and future security threats and assess their severity levels.
• Evaluate the existing security test suite and identify any additional security tests.
• Analyze a given set of security policies and procedures, along with security test results, to determine effectiveness.
• For a given project scenario, identify security test objectives based on functionality, technology attributes and known vulnerabilities.
• Analyze a given situation and determine which security testing approaches are most likely to succeed in that situation.
• Identify areas where additional or enhanced security testing may be needed.
• Evaluate the effectiveness of security mechanisms.
• Help the organization build information security awareness.
• Demonstrate the attacker mentality by discovering key information about a target, performing actions on a test application in a protected environment that a malicious person would perform, and understanding how evidence of the attack could be deleted.
• Analyze a given interim security test status report to determine the level of accuracy, understandability, and stakeholder appropriateness.
• Analyze and document security test needs to be addressed by one or more tools.
• Analyze and select candidate security test tools for a given tool search based on specified needs.
• Understand the benefits of using security testing standards and where to find them.
Module 1: The Basis of Security Testing
Module 2: Security Testing Purposes, Goals and Strategies
Module 3: Security Testing Processes
Module 4: Security Testing Throughout the Software Lifecycle
Module 5: Testing Security Mechanisms
Module 6: Human Factors in Security Testing
Module 7: Security Test Evaluation and Reporting
Module 8: Security Testing Tools
Module 9: Standards and Industry Trends
Other Popular Courses
Executive Cyber Risk Certification (ECRC)
- Duration: 2 Days
- Language: English
- Level: Intermediate
- Exam: ECRC
Mastering Communication & Presentation Te...
- Duration: 4 Days
- Language: Danish
- Level: Intermediate
- Exam: MCPT
Next Generation Mindfulness
- Duration: 1 Days
- Language: English
- Level: Foundation
- Exam: NGM