19.08.2015 Views

4.0

1IZ1TDd

1IZ1TDd

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

26The OWASP Testing FrameworkPhase 5: Maintenance and OperationsPhase 5.1: Conduct Operational Management ReviewsThere needs to be a process in place which details how the operationalside of both the application and infrastructure is managed.Phase 5.2: Conduct Periodic Health ChecksMonthly or quarterly health checks should be performed on boththe application and infrastructure to ensure no new security riskshave been introduced and that the level of security is still intact.Phase 5.3: Ensure Change VerificationAfter every change has been approved and tested in the QA environmentand deployed into the production environment, it is vitalthat the change is checked to ensure that the level of security hasnot been affected by the change. This should be integrated into thechange management process.A Typical SDLC Testing WorkflowThe following figure shows a typical SDLC Testing Workflow.OWASP TESTING FRAMEWORK WORK FLOWBeforeDevelopmentPolicy ReviewReview SDLCProcessStandardsReviewMetricsCriteriaMeasurementTraceabilityDefinitionand DesignRequirementsReviewDesign andArchitectureReviewCreate /Review UMLmodelsCreate /Review ThreatModelsDevelopmentCode ReviewCodeWalkthroughsUnit andSystem testsDeploymentPenetrationTestingConfigurationManagementReviewsUnit andSystem testsAcceptanceTestsMaintenanceChanceverificationHealth ChecksOperationalManagementreviewsRegressionTests

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!