课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Code tests

Code tests

- [Instructor] Code security tests move beyond testing functional requirements and check code for security flaws. While code reviews play an important role in software security, they involve developers examining code and inspecting it for defects. Code tests go beyond code reviews and use technology to assist in the code inspection process. It's common for organizations to use both code tests, and code reviews on the same software to gain different perspectives on software quality. There are three main types of code testing; static application security testing, dynamic application security testing, and interactive application security testing. In a static code test, developers use specialized testing software to examine the code for common defects. The code doesn't actually get executed, but it is examined for common errors, and those errors are reported as defects that require correction. You can think of static code tests as the automated equivalent of a code review. Software…

内容