Involve the security team in software security testing

Involve the security team in software security testing

When the time comes to test the security deliverables of a project, who better to do this than the security experts? Sure we've heard that the information security team needs to be involved in a development since its inception. We've also heard that "checklists" for what needs to be complied with could help the developers ensure all the security "features" have been considered.

But you can prevent more than a headache -- and possibly a "no-go" implementation decision -- if the security team reviews the test script when the code is ready for testing. After all, who knows more about the required security compliance than the information security experts? They may not be able to tell how to do something for any technology used in the department, but they can definitely say what needs to be there.

Ensuring information security experts are in the loop also will prevent miscommunication.

So, when the time comes to test what you've built, remember to involve the security team if there are security-related deliverables or requirements.


    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

This was first published in November 2007

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.