From the course: Complete Guide to Enterprise Cyber Defense
Unlock this course with a free trial
Join today to access over 24,900 courses taught by industry experts.
Forms of testing
From the course: Complete Guide to Enterprise Cyber Defense
Forms of testing
- [Instructor] There are four main forms of testing we undertake as part of our cyber defense to gain assurance that our systems are properly protected. These are testing against predefined test cases to ensure that the security controls work exactly as we predict. This form of testing is used extensively during development and for software and systems acceptance. Sample testing of controls during audits to ensure that the controls have been effective in blocking attacks and continue to be effective. Penetration testing to determine whether a system has weaknesses that can be exploited. A variation of this is red teaming, in which the penetration testing has no specific scope and is carried out covertly, simulating how an adversary would operate. And vulnerability scanning. This is an automated assurance approach, which is specifically focused on identifying known vulnerabilities, which have not been patched.…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.