Domain 6 · 12% of the exam
Security Assessment and Testing
Security assessment determines whether the controls implemented to reduce risk have been implemented as designed, are operating as expected, and are achieving the desired result. This assurance can be the result of outside organizations evaluating the control environment or actions taken by the organization itself to evaluate the performance of the controls. The assessment and testing processes must be performed consistently, and the results communicated properly, so that the organization's management understands the risks they could potentially face. Similarly, audit processes should assure external evaluators of the degree to which an organization's controls meet compliance expectations. Ultimately, the results of audit, assessment, and testing activities will allow the organization to identify control gaps and inefficiencies. This information will be the starting point for continual process improvement activities. The security professional should be familiar with the strategies, techniques, and processes by which organizational expectations for controls are set, evaluated, and improved. They should be able to explain the basic flow of audit and assessment activities and describe the tools and artifacts that support data-driven decisionmaking. Collectively, this information should enable the security professional to develop an organizationally appropriate assessment program.
Progress saved on this device
37 lessons · 177 slides · 86 min read
Learning objectives
- Identify and select security assessment approaches, frameworks, and standards.
- Identify ethical and security implications of various control testing methods.
- Select applicable artifacts to meet compliance requirements (e.g., test results, log files, and other information).
- Explain the need for data-driven security decision-making.
- Identify key activities and process data associated with proper management of security practices.
- Describe organizational response to identified weaknesses.
- Identify exception handling procedures within organizational risk tolerance.
- Apply ethical practices to disclosure of test results.
- Examine the process of conducting security audits.
- Compare the purposes and requirements for conducting different types of audits.
Key topics
- Design and Conduct Assessment and Audit
- Security Controls Testing
- Security Process Data
- Analyze Output and Report
Lessons
- 01Test Coverage AnalysisThe level of structural testing can be evaluated using metrics that are designed to show what percentage of the software structure has been evaluated during structural testing.3 min
- 02Case Study - Ethical Penetration Testing - Coalfire vs. IowaCase studyPlease read the following brief case involving pen testing and answer the following questions to test your own understanding of this technical and ethical subject.2 min
- 03Ethical DisclosureIn the course of an assessment or audit, circumstances may come forward, which might suggest that illegal, unethical or dangerous actions may have been committed by a person or persons within the organization's span of responsibilities or control.4 min
- 04SAS 70 - One Size Wasn’t Supposed to Fit AllWe'll conclude Security Assessment Standards and Frameworks by shifting to SAS 70, in which one size isn't supposed to fit all.4 min
- 05Security Assessment Standards and Frameworks - SOC ReportsThe American Institute of Certified Public Accountants' (AICPA) framework for evaluating internal controls over financial reporting is best known by its System and Organization Control (SOC, pronounced "sock") reports that evaluate organizational controls…3 min
- 06Backup Verification DataPerforming backups is necessary, but it is not the end of the process.1 min
- 07Security Assessment Standards and Frameworks - ISO 27000The ISO 27000 series of standards can be used as an assessment or audit framework for evaluating the effectiveness of an organization's Information Security Management System (ISMS).1 min
- 08Security Assessment Standards and Frameworks - Trust Services CriteriaSecurity Assessment Standards and Frameworks - Trust Services Criteria5 min
- 09Account ManagementThe figure below shows further detail on the never-ending cycle that ensures proper access control.2 min
- 10Ethical Penetration TestingEthical penetration testing simulates real-world attacks, exposes vulnerabilities, verifies defenses, and guides remediation.3 min
- 11Ethical Penetration Testing - Basic MethodologyEthical penetration testing activities are performed in a predictable, defined fashion, which is controlled and specified by a lawful and legally binding contract between the penetration tester and the owners or responsible executive officers of the system…2 min
- 12Testing PerspectivesTesting is generally performed from either an internal or external perspective.2 min
- 13Purpose for the Security Audit and AssessmentThe security audit and assessment identifies vulnerabilities, validates controls, strengthens defenses, and ensures systems, data, infrastructure, and processes meet standards and resist evolving threats.2 min
- 14Security Education, Training, and AwarenessSecurity education builds awareness, reinforces best practices, fosters a culture of vigilance, and equips individuals to recognize, report, and respond effectively to threats.5 min
- 15Negative TestingIn contrast to a positive test (that determines a system works as expected, and, with any error, fails the test); a negative test is designed to provide evidence of the application behavior if there is unexpected or invalid data.1 min
- 16Code Review During Planning and Design and Application and DevelopmentCode Review During Planning and Design and Application and Development2 min
- 17Synthetic TransactionsA process that mingles the information needed by both the operations and assessment communities is evaluating the performance of information systems relative to the effect of the controls in place to protect the system's information. -YTICS DASHBOAR vailab…4 min
- 18Disaster Recovery (DR) and Business Continuity (BC)Although often used together, disaster recovery (DR) and business continuity (BC) are distinct processes.4 min
- 19Availability ServicesAvailability services provide another source for security process data which allows the organization to determine the effectiveness of its controls. The performance of availability services directly affects whether an organization can meet its commitments…2 min
- 20Control Assessment Methods and ToolsControl assessment methods and tools are used to evaluate the effectiveness of security measures, identify weaknesses, and improve an organization's security posture.1 min
- 21Log SecurityWhen needing logs for evidence, organizations can obtain copies of original, centralized, and interpreted log data if the copying and interpretation processes' accuracy are questioned.1 min
- 22Misuse Case TestingMisuse case testing explores how harmful actions, system errors, or hostile inputs could disrupt operations, revealing weaknesses and confirming protections across various interactions between a system and its environment.2 min
- 23Exception HandlingREALL1 min
- 24Continuous Full-Cycle TestingPen testing as an event is a point-in-time activity, reflecting the results of one set of tests against the organization's infrastructure.2 min
- 25Remediation and the Continual Process Improvement CycleOrganizations use various improvement models, such as the PDCA and Six Sigma models, to enhance their cybersecurity posture and operational resilience over time.2 min
- 26Security Assessment Standards and Frameworks - NIST Risk Management FrameworkSecurity Assessment Standards and Frameworks - NIST Risk Management Frameworks1 min
- 27Managed Services and Security AssessmentManaged services and security assessments monitor systems, identify vulnerabilities, validate protections, and deliver expert oversight to ensure resilience against evolving threats.3 min
- 28Interview and TestingInterview3 min
- 29Third-party Audit and AssessmentGay1 min
- 30Logging PracticesEffective log management captures and organizes system activity, monitors for issues, supports audits, and strengthens oversight. aousele big, cite,3 min
- 31Log ReviewsAll of the major controls frameworks emphasize the importance of organizational logging practices.2 min
- 32Management Review and ApprovalManagement reviews ensure security information is used correctly, confirm controls are working as intended, approve changes, and maintain accountability, consistency, transparency, and clear direction. cted mirror mo .c.scene.objects.active = modifier…1 min
- 33Compliance and Substantive TestingCompliance and substantive testing verifies adherence to standards, examines processes, uncovers deficiencies, and validates evidence.1 min
- 34Case Study - WannaCryCase studyThe WannaCry ransomware attack, which unfolded in May 2017, stands as one of the most impactful cyber incidents in history.1 min
- 35Possible Responses (Case Study - WannaCry)Case study answers1. How did the WannaCry incident underscore the importance of ongoing penetration testing beyond the initial system setup?1 min
- 36External Audit and AssessmentExternal audits and assessments offer independent oversight, confirm compliance, identify weaknesses, and recommend improvements.3 min
- 37Internal Audit and AssessmentInternal audits and assessments evaluate controls, verify compliance, uncover weaknesses, and guide improvements.5 min
