All domains

Domain 6 · 12% of the exam

Security Assessment and Testing

Security assessment determines whether the controls implemented to reduce risk have been implemented as designed, are operating as expected, and are achieving the desired result. This assurance can be the result of outside organizations evaluating the control environment or actions taken by the organization itself to evaluate the performance of the controls. The assessment and testing processes must be performed consistently, and the results communicated properly, so that the organization's management understands the risks they could potentially face. Similarly, audit processes should assure external evaluators of the degree to which an organization's controls meet compliance expectations. Ultimately, the results of audit, assessment, and testing activities will allow the organization to identify control gaps and inefficiencies. This information will be the starting point for continual process improvement activities. The security professional should be familiar with the strategies, techniques, and processes by which organizational expectations for controls are set, evaluated, and improved. They should be able to explain the basic flow of audit and assessment activities and describe the tools and artifacts that support data-driven decisionmaking. Collectively, this information should enable the security professional to develop an organizationally appropriate assessment program.

Learning objectives

  • Identify and select security assessment approaches, frameworks, and standards.
  • Identify ethical and security implications of various control testing methods.
  • Select applicable artifacts to meet compliance requirements (e.g., test results, log files, and other information).
  • Explain the need for data-driven security decision-making.
  • Identify key activities and process data associated with proper management of security practices.
  • Describe organizational response to identified weaknesses.
  • Identify exception handling procedures within organizational risk tolerance.
  • Apply ethical practices to disclosure of test results.
  • Examine the process of conducting security audits.
  • Compare the purposes and requirements for conducting different types of audits.

Key topics

  • Design and Conduct Assessment and Audit
  • Security Controls Testing
  • Security Process Data
  • Analyze Output and Report

Lessons

Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.

  1. 01Test Coverage AnalysisThe level of structural testing can be evaluated using metrics that are designed to show what percentage of the software structure has been evaluated during structural testing.6 slides · 3 min read
  2. 02Case Study - Ethical Penetration Testing - Coalfire vs. IowaCase studyPlease read the following brief case involving pen testing and answer the following questions to test your own understanding of this technical and ethical subject.5 slides · 2 min read
  3. 03Ethical DisclosureIn the course of an assessment or audit, circumstances may come forward, which might suggest that illegal, unethical or dangerous actions may have been committed by a person or persons within the organization's span of responsibilities or control.8 slides · 4 min read
  4. 04SAS 70 - One Size Wasn’t Supposed to Fit AllWe'll conclude Security Assessment Standards and Frameworks by shifting to SAS 70, in which one size isn't supposed to fit all.10 slides · 4 min read
  5. 05Security Assessment Standards and Frameworks - SOC ReportsThe American Institute of Certified Public Accountants' (AICPA) framework for evaluating internal controls over financial reporting is best known by its System and Organization Control (SOC, pronounced "sock") reports that evaluate organizational controls…9 slides · 3 min read
  6. 06Backup Verification DataPerforming backups is necessary, but it is not the end of the process.4 slides · 1 min read
  7. 07Security Assessment Standards and Frameworks - ISO 27000The ISO 27000 series of standards can be used as an assessment or audit framework for evaluating the effectiveness of an organization's Information Security Management System (ISMS).3 slides · 1 min read
  8. 08Security Assessment Standards and Frameworks - Trust Services CriteriaSecurity Assessment Standards and Frameworks - Trust Services Criteria13 slides · 5 min read
  9. 09Account ManagementThe figure below shows further detail on the never-ending cycle that ensures proper access control.4 slides · 2 min read
  10. 10Ethical Penetration TestingEthical penetration testing simulates real-world attacks, exposes vulnerabilities, verifies defenses, and guides remediation.4 slides · 3 min read
  11. 11Ethical Penetration Testing - Basic MethodologyEthical penetration testing activities are performed in a predictable, defined fashion, which is controlled and specified by a lawful and legally binding contract between the penetration tester and the owners or responsible executive officers of the system…6 slides · 2 min read
  12. 12Testing PerspectivesTesting is generally performed from either an internal or external perspective.4 slides · 2 min read
  13. 13Purpose for the Security Audit and AssessmentThe security audit and assessment identifies vulnerabilities, validates controls, strengthens defenses, and ensures systems, data, infrastructure, and processes meet standards and resist evolving threats.3 slides · 2 min read
  14. 14Security Education, Training, and AwarenessSecurity education builds awareness, reinforces best practices, fosters a culture of vigilance, and equips individuals to recognize, report, and respond effectively to threats.5 slides · 5 min read
  15. 15Negative TestingIn contrast to a positive test (that determines a system works as expected, and, with any error, fails the test); a negative test is designed to provide evidence of the application behavior if there is unexpected or invalid data.2 slides · 1 min read
  16. 16Code Review During Planning and Design and Application and DevelopmentCode Review During Planning and Design and Application and Development7 slides · 2 min read
  17. 17Synthetic TransactionsA process that mingles the information needed by both the operations and assessment communities is evaluating the performance of information systems relative to the effect of the controls in place to protect the system's information. -YTICS DASHBOAR vailab…10 slides · 4 min read
  18. 18Disaster Recovery (DR) and Business Continuity (BC)Although often used together, disaster recovery (DR) and business continuity (BC) are distinct processes.8 slides · 4 min read
  19. 19Availability ServicesAvailability services provide another source for security process data which allows the organization to determine the effectiveness of its controls. The performance of availability services directly affects whether an organization can meet its commitments…4 slides · 2 min read
  20. 20Control Assessment Methods and ToolsControl assessment methods and tools are used to evaluate the effectiveness of security measures, identify weaknesses, and improve an organization's security posture.2 slides · 1 min read
  21. 21Log SecurityWhen needing logs for evidence, organizations can obtain copies of original, centralized, and interpreted log data if the copying and interpretation processes' accuracy are questioned.3 slides · 1 min read
  22. 22Misuse Case TestingMisuse case testing explores how harmful actions, system errors, or hostile inputs could disrupt operations, revealing weaknesses and confirming protections across various interactions between a system and its environment.3 slides · 2 min read
  23. 23Exception HandlingREALL3 slides · 1 min read
  24. 24Continuous Full-Cycle TestingPen testing as an event is a point-in-time activity, reflecting the results of one set of tests against the organization's infrastructure.4 slides · 2 min read
  25. 25Remediation and the Continual Process Improvement CycleOrganizations use various improvement models, such as the PDCA and Six Sigma models, to enhance their cybersecurity posture and operational resilience over time.4 slides · 2 min read
  26. 26Security Assessment Standards and Frameworks - NIST Risk Management FrameworkSecurity Assessment Standards and Frameworks - NIST Risk Management Frameworks2 slides · 1 min read
  27. 27Managed Services and Security AssessmentManaged services and security assessments monitor systems, identify vulnerabilities, validate protections, and deliver expert oversight to ensure resilience against evolving threats.4 slides · 3 min read
  28. 28Interview and TestingInterview4 slides · 3 min read
  29. 29Third-party Audit and AssessmentGay2 slides · 1 min read
  30. 30Logging PracticesEffective log management captures and organizes system activity, monitors for issues, supports audits, and strengthens oversight. aousele big, cite,4 slides · 3 min read
  31. 31Log ReviewsAll of the major controls frameworks emphasize the importance of organizational logging practices.4 slides · 2 min read
  32. 32Management Review and ApprovalManagement reviews ensure security information is used correctly, confirm controls are working as intended, approve changes, and maintain accountability, consistency, transparency, and clear direction. cted mirror mo .c.scene.objects.active = modifier…3 slides · 1 min read
  33. 33Compliance and Substantive TestingCompliance and substantive testing verifies adherence to standards, examines processes, uncovers deficiencies, and validates evidence.2 slides · 1 min read
  34. 34Case Study - WannaCryCase studyThe WannaCry ransomware attack, which unfolded in May 2017, stands as one of the most impactful cyber incidents in history.5 slides · 1 min read
  35. 35Possible Responses (Case Study - WannaCry)Case study answers1. How did the WannaCry incident underscore the importance of ongoing penetration testing beyond the initial system setup?1 slides · 1 min read
  36. 36External Audit and AssessmentExternal audits and assessments offer independent oversight, confirm compliance, identify weaknesses, and recommend improvements.5 slides · 3 min read
  37. 37Internal Audit and AssessmentInternal audits and assessments evaluate controls, verify compliance, uncover weaknesses, and guide improvements.7 slides · 5 min read