Manual assessment.
WHAT IT INVOLVES
A skilled tester attempting to find and exploit weaknesses within the agreed scope.
WHAT IT FINDS THAT SCANNING DOES NOT
Logic flaws Chains of minor issues that combine into serious ones Access control failures Issues requiring understanding of the application
WHY CHAINS MATTER
Serious compromises frequently result from several small issues combined, none serious alone.
WHAT A TEST TYPICALLY COVERS
Discovery of what exists Identification of weaknesses Verification by attempting exploitation Establishing what could be reached Documentation
WHY EXPLOITATION IS INCLUDED
It distinguishes theoretical issues from real ones.
WHAT TO ESTABLISH
Whether exploitation is permitted, and to what extent.
WHAT LIMITS TO SET
No disruption to production No extraction of real data No further compromise once access is proven
WHY ONCE ACCESS IS PROVEN
Continuing beyond proof adds risk without adding information.
WHAT APPLICATION TESTING EXAMINES
Authentication and session handling Access control between users and roles Input handling Business logic Data exposure Configuration
WHY ACCESS CONTROL BETWEEN USERS
It is among the commonest serious findings and scanners cannot detect it.
WHAT TO ESTABLISH
That multiple user roles are provided for testing.
WHY
Testing with one account cannot find access control failures.
WHAT INFRASTRUCTURE TESTING EXAMINES
Exposed services Patch levels Configuration and hardening Credentials and authentication Network segregation
WHAT TO EXPECT
Findings, including ones you did not anticipate.
WHAT TO ESTABLISH
That the objective is finding problems, not passing.