What do you dislike about Security testing?
1. Sometimes scan results are false positive or false negative
2. Small mistakes can be costly and cause a lot of damage
3. Scan results assessment should be done very carefully Review collected by and hosted on G2.com.
Recommendations to others considering Security testing:
Security testing should be an integral part of the testing life cycle and should be conducted before any major production release.
Security testing can be started with manual testing like covering authorization and authentication part and then move to automated scans covering top 10 vulnerabilities guidelines published by OWASP. OWASP Zed Attack Proxy is a good open-source tool to conduct Active/passive scans on any web application. Review collected by and hosted on G2.com.
What problems is Security testing solving and how is that benefiting you?
Security testing is useful to identify the security vulnerabilities in the web application. It can be done in a manual and automated way using various tools. Majorly the threats can be categorized in the OWASP top 10 security threats which have certain recommendations to be followed in application design and coding practices, server configurations etc.
It is desired and sometimes mandatory to conduct security tests for various software products before these are out in the market. It builds trust with customers. It is possible that a small unidentified threat can cause a major financial loss so security testing should be done thoroughly and with utmost care. Review collected by and hosted on G2.com.