Security scanning is a systematic approach to automated and manual testing of software and infrastructure for vulnerabilities. It combines static, dynamic and dependency analyses to detect risks early. It is integrated into CI/CD pipelines and operations to prevent regressions and meet compliance requirements.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Security scanning systematically examines systems, applications, or dependencies for known security risks.
Security scanning grew from the need to repeat security checks throughout development and operations. OWASP ZAP is an open-source tool for automated and manual web application testing.
Scanners send probes or analyze artifacts and report signals using rules and signatures. Findings require validation, prioritization, and remediation; a scan only finds risks covered by its tests and detection methods.
Automated checks search systematically for signs of security problems.
Requests or artifacts are tested against detection rules and emitted as findings.
Coverage, safe test environments, and manual validation limit results and risk.
Security scanning enables repeatable security checks in development and operational workflows.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.