Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

ISTQB Advanced - Security Tester

( Duration: 4 Days )

In ISTQB Advanced - Security Tester training course, you will learn to plan, perform and evaluate security tests from a variety of perspectives, including policy, risk, standards, requirements and vulnerability. You will learn to align security test activities with project lifecycle activities, and analyse effectiveness of risk assessment techniques. You will also be able to determine the best security test tools based on specified needs.

By attending ISTQB Advanced - Security Tester workshop, delegates will learn to:

  • Plan, perform and evaluate security tests from a variety of perspectives - policy-based, risk-based, standards-based, requirements-based and vulnerability-based.
  • Align security test activities with project lifecycle activities.
  • Analyze the effective use of risk assessment techniques in a given situation to identify current and future security threats and assess their severity levels.
  • Evaluate the existing security test suite and identify any additional security tests.
  • Analyze a given set of security policies and procedures, along with security test results, to determine effectiveness.
  • For a given project scenario, identify security test objectives based on functionality, technology attributes and known vulnerabilities.
  • Analyze a given situation and determine which security testing approaches are most likely to succeed in that situation.
  • Identify areas where additional or enhanced security testing may be needed.
  • Evaluate effectiveness of security mechanisms.
  • Help the organization build information security awareness.
  • Demonstrate the attacker mentality by discovering key information about a target, performing actions on a test application in a protected environment that a malicious person would perform, and understand how evidence of the attack could be deleted.
  • Analyze a given interim security test status report to determine the level of accuracy, understandability, and stakeholder appropriateness.
  • Analyze and document security test needs to be addressed by one or more tools.
  • Analyze and select candidate security test tools for a given tool search based on specified needs.
  • Understand the benefits of using security testing standards and where to find them.

The ISTQB Advanced - Security Tester class is ideal for:

  • Software Testers who holds the ISTQB Certified Tester, Foundation Level (CTFL) and want to expand their knowledge of security testing,
  • Security Testers who holds the CTFL and wish to obtain an advanced certification to solidify their knowledge,
  • Security Administrators who wants to learn more about how to test the security defenses in their organization, and
  • Anyone who wants to learn more about security testing but do not necessarily want to take the CTAL-SEC exam.

COURSE AGENDA

1

The Basis of Security Testing

  • Security Risks
  • Information Security Policies and Procedures
  • Security Auditing and Its Role in Security Testing
2

Security Testing Purposes, Goals and Strategies

  • Introduction
  • The Purpose of Security Testing
  • The Organizational Context
  • Security Testing Objectives
  • The Scope and Coverage of Security Testing Objectives
  • Security Testing Approaches
  • Improving the Security Testing Practices
3

Security Testing Processes

  • Security Test Process Definition
  • Security Test Planning
  • Security Test Design
  • Security Test Execution
  • Security Test Evaluation
  • Security Test Maintenance
4

Security Testing Throughout the Software Lifecycle

  • Role of Security Testing in a Software Lifecycle
  • The Role of Security Testing in Requirements
  • The Role of Security Testing in Design
  • The Role of Security Testing in Implementation Activities
  • The Role of Security Testing in System and Acceptance Test Activities
  • The Role of Security Testing in Maintenance
5

Testing Security Mechanisms

  • System Hardening
  • Authentication and Authorization
  • Encryption
  • Firewalls and Network Zones
  • Intrusion Detection
  • Malware Scanning
  • Data Obfuscation
  • Training
6

Human Factors in Security Testing

  • Understanding the Attackers
  • Social Engineering
  • Security Awareness
7

Security Test Evaluation and Reporting

  • Security Test Evaluation
  • Security Test Reporting
8

Security Testing Tools

  • Types and Purposes of Security Testing Tools
  • Tool Selection
9

Standards and Industry Trends

  • Understanding Security Testing Standards
  • Applying Security Standards
  • Industry Trends

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X