Security testing is a structured method to identify vulnerabilities and weaknesses across applications, infrastructure and development processes. It combines automated scans, manual penetration tests and threat-informed reviews to prioritize risks and verify remediations. Applicable at design, build, and operation phases to reduce breach likelihood and impac…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Security testing systematically examines whether a system has weaknesses and can resist intended or accidental attacks.
Security testing grew from combining software testing with information security. As connected web applications expanded, structured practices such as the OWASP Web Security Testing Guide organized common attack paths and checks.
View the system as a potential attacker would: map the attack surface, formulate relevant threats, test them with suitable techniques, and assess the evidence. Findings lead to prioritized fixes and a retest.
It includes reachable functions, interfaces, and components.
A vulnerability enables or facilitates an unwanted effect.
Test results show which security assumptions were examined.
Security testing exposes technical risks before they become incidents. It supports secure development, acceptance, and ongoing operations.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.