moksh
Joined: 31 Aug 2007 Posts: 17
|
Posted: Thu Sep 06, 2007 7:57 am Post subject: Inputs for WBST... |
|
|
Below are the inputs for white box security testing (WBST)
Code
Security requirements
Design documents
Architecture and design risk analysis document
In addition to above, we will also need to know quality requirement for the system in terms of performance and response. So we maintain an optimum level of security with desired performance. This is particularly important in Web services where the performance is greatly affected if security overheads are included. The Risk Analysis document should help identify the Threats/Vulnerabilities in components, Business Impact of these vulnerabilities, probability of occurrence of threat/vulnerabilities and Existing and recommended measure to counter risks.
This document will be basis for developing the test strategy and planning for security. |
|