Domain 6: Security Assessment and Testing

Video transcripts

Every course video in Domain 6, written out with timestamps so you can search the wording instead of scrubbing through playback.

  • Transcript

    1. 0:00At Greenburst Tech,
    2. 0:01a startup building a new budgeting app,
    3. 0:03the team is getting ready to launch their first product.
    4. 0:06The stakes are high as the development wraps up,
    5. 0:09their lead developer Ayesha
    6. 0:11meets with the security consultant Marcus to ensure the code is clean,
    7. 0:16secure,
    8. 0:16and ready for deployment.
    9. 0:18Marcus reminds the team.
    10. 0:20Code review isn't just about catching typos.
    11. 0:23It's about confirming that every piece of code serves a purpose,
    12. 0:26meets security standards,
    13. 0:28and contains no hidden or dead end logic.
    14. 0:30They focus on 6 key checks.
    15. 0:33Does the app do everything it's supposed to?
    16. 0:35Is there any leftover or unused code?
    17. 0:38Has any backdoor or test mode been left in?
    18. 0:41Were coding standards followed?
    19. 0:43Did all code come from trusted sources?
    20. 0:45Can every line of code actually be reached and run?
    21. 0:48To handle their 50,000 lines of code,
    22. 0:51the team uses automated static analysis tools.
    23. 0:54Ayesha runs a static application security test.
    24. 0:57It flags some deprecated libraries and a few hardcoded credentials.
    25. 1:02Marcus steps in to explain.
    26. 1:04These tools scan your code without executing it.
    27. 1:07It's efficient and accurate,
    28. 1:09especially when you're developing on a fast cycle like Agile or DevOps.
    29. 1:13Before deeper testing,
    30. 1:14the team gathers to review the app's architecture.
    31. 1:17They map how the app handles sensitive data and user sessions.
    32. 1:21Marcus guides them through a threat modeling exercise.
    33. 1:24What can go.
    34. 1:24Wrong here who might try to exploit this?
    35. 1:27Where are we most vulnerable?
    36. 1:29They discover that their login system lacks
    37. 1:32proper throttling against brute force attacks.
    38. 1:34It's an early catch that saves them future trouble with a beta version compiled,
    39. 1:39the team performs a manual binary review,
    40. 1:42though not as detailed as source analysis.
    41. 1:44It helps ensure.
    42. 1:45No vulnerabilities sneak in during the build process.
    43. 1:49They also confirm all third party code used is verified and licensed properly.
    44. 1:54Ayesha summarizes what they've gained.
    45. 1:56We found real issues early.
    46. 1:58We kept our app aligned with secure coding standards,
    47. 2:01and we've documented everything in case we ever need to prove our process.
    48. 2:05Marcus adds this is about protecting your users and your business.
    49. 2:09Good code review is smart business.
    Open in the ISC2 portal