Security Starts with Requirements


necessary to conduct exploratory security testing without adequate requirements.

Starting the software development project off with effective security requirements ensures that the quality assurance team will be able to address security in its project planning, during testing tool acquisitions, and in test coverage. With security requirements, team members can make educated decisions about the types of application security testing they are expected to conduct.

Early security testing planning provides quality assurance planners with insight into what portions of the security testing challenge are outside of their scope and need to be assigned to the security team, like network security and production environment configuration.


