01.09.2015 Views

4.0

1NSchAb

1NSchAb

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

26<br />

The OWASP Testing Framework<br />

Phase 5: Maintenance and Operations<br />

Phase 5.1: Conduct Operational Management Reviews<br />

There needs to be a process in place which details how the operational<br />

side of both the application and infrastructure is managed.<br />

Phase 5.2: Conduct Periodic Health Checks<br />

Monthly or quarterly health checks should be performed on both<br />

the application and infrastructure to ensure no new security risks<br />

have been introduced and that the level of security is still intact.<br />

Phase 5.3: Ensure Change Verification<br />

After every change has been approved and tested in the QA environment<br />

and deployed into the production environment, it is vital<br />

that the change is checked to ensure that the level of security has<br />

not been affected by the change. This should be integrated into the<br />

change management process.<br />

A Typical SDLC Testing Workflow<br />

The following figure shows a typical SDLC Testing Workflow.<br />

OWASP TESTING FRAMEWORK WORK FLOW<br />

Before<br />

Development<br />

Policy Review<br />

Review SDLC<br />

Process<br />

Standards<br />

Review<br />

Metrics<br />

Criteria<br />

Measurement<br />

Traceability<br />

Definition<br />

and Design<br />

Requirements<br />

Review<br />

Design and<br />

Architecture<br />

Review<br />

Create /<br />

Review UML<br />

models<br />

Create /<br />

Review Threat<br />

Models<br />

Development<br />

Code Review<br />

Code<br />

Walkthroughs<br />

Unit and<br />

System tests<br />

Deployment<br />

Penetration<br />

Testing<br />

Configuration<br />

Management<br />

Reviews<br />

Unit and<br />

System tests<br />

Acceptance<br />

Tests<br />

Maintenance<br />

Chance<br />

verification<br />

Health Checks<br />

Operational<br />

Management<br />

reviews<br />

Regression<br />

Tests

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!