# Discussion: Security Testing

**URL:** <https://club.ministryoftesting.com/t/discussion-security-testing/49817>\
**Category:** 🗓️ Events\
**Tags:** security, panel, discussions\
**Created:** [4 May 2021 07:00 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817 "2021-05-04T07:00:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![heather\_reid](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/heather_reid/32/29_2.png) [@heather\_reid](https://club.ministryoftesting.com/u/heather_reid)\
**Post date:** [4 May 2021 07:00 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817/1 "2021-05-04T07:00:23Z")

</div>

Tonight, @testerfromleic will be joined by three fantastically knowledgeable guests @saskia, @anneoikarinen and @coffeefueled to talk about security testing 🔒

We’ll use this thread to add questions we don’t get to during the session and any resources that the presenters mention.

If you’d like to continue the conversation from the session, this thread is an excellent place to do that 😁 Share resources and follow up success stories from your learnings here!

# Questions we didn’t get to

1. @dancaseley: Is security testing a “thing” in its own right, or is it an aspect of every other type of testing? Or is that just a lens thing?
2. @dancaseley: Security testing suffers the same fate as a lot of other non-feature-driven types of testing. It happens at the end, like performance and accessibility testing. What kinds of security testing activity can I schedule for Sprint 0 & 1?
3. @dancaseley: How could you estimate the amount of time required for security testing activities at the beginning of a project? This is sometimes a necessary evil of an agency model, and without it they might get skipped.
4. @dancaseley: What can we do to ensure the security of testing itself? That tests or pipelines aren’t interfered with, that results can be depended upon, that vulnerabilities haven’t been suppressed, etc?
5. @dancaseley: I’ve got a low severity CVE in a dependency. A new version was released today, which, among other things, fixes it. Do I always update? Aren’t there other inherent security risks? For instance, should I be trying to pentest all of my dependency updates?
6. @viola: If you are given an app and you are given a chance to test just 1 idea, what would you selectwith number one priority?
7. @dancaseley: If I’m not a bank or a civil servant, are adversaries at the sophistication level of nation states something I should worry about, or include in any threat modelling?
8. @andy_hird: If not certification, what do hiring managers look for in beginner security testers?
9. @bjpalmz: How do you promote good security practices as the only tester in a team?
10. @dancaseley: To what extent do NCSC (or country-local equivalent) represent “best in class” advice for cyber security?

---

<div class="post-metadata">

**Author:** ![heather\_reid](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/heather_reid/32/29_2.png) [@heather\_reid](https://club.ministryoftesting.com/u/heather_reid)\
**Post date:** [4 May 2021 20:12 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817/2 "2021-05-04T20:12:28Z")

</div>

# Resources mentioned

Saskia’s Manchester talk

> **[Threat Modelling: How Software Survives in a Hacker’s Universe Saskia Coplans](https://www.ministryoftesting.com/testbash-sessions/threat-modelling-how-software-survives-in-a-hacker-s-universe-saskia-coplans)**
>
> Watch "TThreat Modelling: How Software Survives in a Hacker’s Universe" with Saskia Coplans from TestBash Manchester 2019

Anne’s TestBash Home talk

> **[Evil User Stories - Improve Your Application Security - Anne Oikarinen](https://www.ministryoftesting.com/testbash-sessions/evil-user-stories-improve-your-application-security-anne-oikarinen)**
>
> Evil User Stories - Improve Your Application Security - Anne Oikarinen

Elevation of Privilege (EoP) Threat Modeling Card Game  
[https://www.microsoft.com/en-gb/download/details.aspx?id=20303](https://www.microsoft.com/en-gb/download/details.aspx?id=20303)

Cyber Bogies

> **[GitHub - nixu-corp/NixuCyberBogies: Cyber Bogies are our gallery of "usual suspects"](https://github.com/nixu-corp/NixuCyberBogies)**
>
> Cyber Bogies are our gallery of "usual suspects"

LINDDUN GO

> **[GO | linddun.org](https://linddun.org/go/)**

> **[Elevation of Privilege (EoP) Threat Modeling Card Game](https://agilestationery.com/products/elevation-of-privilege-game)**
>
> Bulk Pricing (automatically applied at checkout) Qty Discount 5+ 10% off 10+ 15% off 20+ 20% off 30+ 30% off   The Elevation of Privilege (EoP) card game offers a structured and engaging approach to threat modeling, enabling development teams to...

James recommended this book to learn about thread modelling

> **[Threat Modeling: Designing for Security](https://shostack.org/books/threat-modeling-book)**

Club threads on getting started in certain specialities, security included [Club Posts To Help You Get Started With Software Testing And QA](https://club.ministryoftesting.com/t/club-posts-to-help-you-get-started-with-software-testing-and-qa/17183)

> **[OWASP Juice Shop | OWASP Foundation](https://owasp.org/www-project-juice-shop/)**
>
> Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!

> **[TryHackMe | Cyber Security Training](https://tryhackme.com/)**
>
> TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

> **[Cyber Mastery: Community Inspired. Enterprise Trusted.](https://www.hackthebox.com/)**
>
> We raise your cyber resilience by transforming technical teams into a mission-ready workforce, so every organization can stay ahead of tomorrow’s threats. Get started now with personal or team plans.

> **[Vulnerable By Design ~ VulnHub](https://www.vulnhub.com/)**
>
> VulnHub provides materials allowing anyone to gain practical hands-on experience with digital security, computer applications and network administration tasks.

OffSec do a couple of free courses: [https://kali.training/](https://kali.training/) and [Metasploit Unleashed | Metasploit Unleashed - Free Online Ethical Hacking Course](https://www.offensive-security.com/metasploit-unleashed/)

[https://twitter.com/zackwhittaker](https://twitter.com/zackwhittaker)

[https://twitter.com/cybergibbons](https://twitter.com/cybergibbons)

**Tools**  
[https://www.rexscan.com/](https://www.rexscan.com/)

> **[Burp - Web Application Security, Testing, & Scanning - PortSwigger](https://portswigger.net/burp)**
>
> PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.

> **[The ZAP Homepage](https://www.zaproxy.org/)**
>
> Welcome to ZAP!

---

<div class="post-metadata">

**Author:** ![coffeefueled](https://avatars.discourse-cdn.com/v4/letter/c/67e7ee/32.png) [@coffeefueled](https://club.ministryoftesting.com/u/coffeefueled)\
**Post date:** [4 May 2021 22:05 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817/3 "2021-05-04T22:05:45Z")

</div>

To throw in my own answers (which are not authoritative, just mine):

> [@heather\_reid](#):
>
> - @dancaseley: Is security testing a “thing” in its own right, or is it an aspect of every other type of testing? Or is that just a lens thing?

Perfect world answer, security is simply an aspect of everything else, not a separate area at all. That applies to testing as much as anything else. This only works when every area of a business and every person is able to (as in has the expertise, resources, and autonomy) take ownership of their own area of security.

> [@heather\_reid](#):
>
> - @dancaseley: Security testing suffers the same fate as a lot of other non-feature-driven types of testing. It happens at the end, like performance and accessibility testing. What kinds of security testing activity can I schedule for Sprint 0 & 1?

Threat modelling at sprint 0, which can inform design principles and functional testing for each subsequent sprint. In sprint 1, update the threat model (also at every subsequent sprint - unless you can fully test everything you need something to guide your security testing, and that’s the purpose of a threat model).

> [@heather\_reid](#):
>
> - @dancaseley: How could you estimate the amount of time required for security testing activities at the beginning of a project? This is sometimes a necessary evil of an agency model, and without it they might get skipped.

Flippant answer, make an estimate and double it. It’s a hard one to answer without more detail. If you take security as a functional requirement (looking at misuse cases throughout the process as an example) then you can use the same methods as for any other testing. For the final penetration testing step, it’s more a case of deciding what your risk appetite is, and a conversation with your pen testers will be able to help with that.

> [@heather\_reid](#):
>
> - @dancaseley: What can we do to ensure the security of testing itself? That tests or pipelines aren’t interfered with, that results can be depended upon, that vulnerabilities haven’t been suppressed, etc?

That’s looking into integrity testing, so version control, good change management, solid audit trails, will all help. Particularly around findings from security testing, having strong risk management and ensuring that ownership of findings is recorded and attributable to an identifiable accountable person is key.

> [@heather\_reid](#):
>
> - @dancaseley: I’ve got a low severity CVE in a dependency. A new version was released today, which, among other things, fixes it. Do I always update? Aren’t there other inherent security risks? For instance, should I be trying to pentest all of my dependency updates?

Risk appetite is key here. There is no absolute answer. What’s the impact of the CVE, is it viable for an actual attack? Does the update break anything or raise any other risks? Pen testing all dependency updates isn’t realistically going to happen, and would slow the update cycle to a crawl in any case. This needs a dialogue with the wider business to understand the priorities and risk appetite, and with the security team to make sure that risk appetite translates into appropriate action.

> [@heather\_reid](#):
>
> - @viola: If you are given an app and you are given a chance to test just 1 idea, what would you selectwith number one priority?

Thoroughly fuzzing every input.

> [@heather\_reid](#):
>
> - @dancaseley: If I’m not a bank or a civil servant, are adversaries at the sophistication level of nation states something I should worry about, or include in any threat modelling?

When teaching threat modelling I often use the example of an alien invasion. Making sure the threats you are working with are realistic is key, as it’s perfectly possible to dive down a rabbit hole, concerning yourselves with threats that take more resources than are ever going to be provided to mitigate, and/or which are never going to concern themselves with your systems.

> [@heather\_reid](#):
>
> - @andy_hird: If not certification, what do hiring managers look for in beginner security testers?

One way I’ve seen successfully used a lot is speaking at rookie conferences, writing about what you’re learning, and generally talking about things. Hiring managers are actively looking for people, and putting out content on topics that interest you seems to be successful at drawing attention of hiring managers, particularly where you’re talking about a niche topic.

> [@heather\_reid](#):
>
> - @bjpalmz: How do you promote good security practices as the only tester in a team?

I’ve not been in this situation, but I have found that generally people actively want to do security right when they understand it and feel that they can do something about it.

> [@heather\_reid](#):
>
> - @dancaseley: To what extent do NCSC (or country-local equivalent) represent “best in class” advice for cyber security?

No one-size-fits-all advice will ever be best in class, but NCSC and similar do put out good basic advice. It will never compare to a proper assessment that puts work into understanding individual organisation context, but is worth following if you don’t have that option.

---

<div class="post-metadata">

**Author:** ![heather\_reid](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/heather_reid/32/29_2.png) [@heather\_reid](https://club.ministryoftesting.com/u/heather_reid)\
**Post date:** [10 May 2021 09:02 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817/4 "2021-05-10T09:02:38Z")

</div>

The recording is now live 🎉

> **[Discussion: Security Testing](https://www.ministryoftesting.com/dojo/lessons/discussion-security-testing)**
>
> Learn more about Security Testing - from useful tools and keeping up with emerging threats through to industry leaders that you should follow.

---

<div class="post-metadata">

**Author:** ![dancaseley](https://avatars.discourse-cdn.com/v4/letter/d/ba9def/32.png) [@dancaseley](https://club.ministryoftesting.com/u/dancaseley)\
**Post date:** [3 May 2023 09:05 UTC](https://club.ministryoftesting.com/t/discussion-security-testing/49817/5 "2023-05-03T09:05:16Z")

</div>

Hey @coffeefueled - I just wanted to circle back round and thank you for the follow-up answers - I’ve referred to them a bunch of times over the last couple of years when deciding where the “edges” are. Much appreciated!
