COURSE OBJECTIVE:
This course is aimed at the softer-side of security testing and addresses the following key elements and how we manage them from a testing perspective through the life cycle from inception to delivery, including: • Human lapses • Malicious insiders • Malicious outsiders • Lack of adequate defenses and testing of the defenses that are in place • Defective software in general • A limited view of security and testing • Placing too much trust in technology • Security is an afterthought in most development projects • Lack of awareness at the executive level. Everybody knows cybersecurity is a problem, but very few people know how to deal with the risks and challenges.
TARGET AUDIENCE:
The ISTQB Advanced Security course is for Technical Testers, Security Testers, Security Co-ordinators and Managers, plus testers and test managers who are serious about including security aspects into their test plans or who want to specialise.
COURSE PREREQUISITES:
• A Certificate at ISTQB Foundation level must have been awarded for candidates to sit this course • It is recommended that candidates have at least three-years testing experience before attempting the course and exam.
COURSE CONTENT:
Module 1 – The Basis of Security Testing • Security Risks • Information Security Policies and Procedures • Security Auditing and Its Role in Security Testing.Module 2 – Security Testing Purposes, Goals and Strategies • Introduction • The Purpose of Security Testing • The Organizational Context • Security Testing Objectives • The Scope and Coverage of Security Testing Objectives. • Security Testing Approaches • Improving the Security Testing Practices • ISTQB Advanced Security Tester Certification Course.Module 3 – Security Testing Processes • Security Test Process Definition • Security Test Planning • Security Test Design • Security Test Execution • Security Test Evaluation • Security Test Maintenance.Module 4 – Security Testing Throughout the Software Lifecycle • Role of Security Testing in a Software Lifecycle • The Role of Security Testing in Requirements • The Role of Security Testing in Design • The Role of Security Testing in Implementation Activities • The Role of Security Testing in System and Acceptance Test Activities • The Role of Security Testing in Maintenance.Module 5 – Testing Security Mechanisms • System Hardening • Authentication and Authorization • Encryption • Firewalls and Network Zones • Intrusion Detection • Malware Scanning • Data Obfuscation • Training.Module 6 – Human Factors in Security Testing
• Understanding the Attackers • Social Engineering • Security Awareness.Module 7 – Security Test Evaluation and Reporting
• Security Test Evaluation • Security Test Reporting.Module 8 – Security Testing Tools • Types and Purposes of Security Testing Tools • Tool Selection.Module 9 – Standards and Industry Trends • Understanding Security Testing Standards • Applying Security Standards • Industry Trends.
FOLLOW ON COURSES:
Holders of this certificate might also consider other ISTQB Advanced courses, includng- ISTQB Test
Analyst
– ISTQB Technical
Test Analyst
– ISTQB Agile
Technical Tester
– ISTQB Automation
Engineer
– ISTQB Test
Manager