From the course: Complete Guide to Enterprise Cyber Defense

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Forms of testing

Forms of testing

- [Instructor] There are four main forms of testing we undertake as part of our cyber defense to gain assurance that our systems are properly protected. These are testing against predefined test cases to ensure that the security controls work exactly as we predict. This form of testing is used extensively during development and for software and systems acceptance. Sample testing of controls during audits to ensure that the controls have been effective in blocking attacks and continue to be effective. Penetration testing to determine whether a system has weaknesses that can be exploited. A variation of this is red teaming, in which the penetration testing has no specific scope and is carried out covertly, simulating how an adversary would operate. And vulnerability scanning. This is an automated assurance approach, which is specifically focused on identifying known vulnerabilities, which have not been patched.…

Contents