Please explain the strategies for security testing?

Question by raj_kishore78: Please explain the strategies for security testing?
I want to perform security testing for a web application? Which are best tools which can be used? How to perform regression testing for security testing of an application- especially for XSS and SQL Injection?

Best answer:

Answer by MJ23_4life
OSSTMM – Open Source Security Testing Methodology Manual by Pete Herzog

The Open Source Security Testing Methodology Manual (OSSTMM) is a peer-reviewed methodology for performing security tests and metrics. The OSSTMM test cases are divided into five channels (sections) which collectively test: information and data controls, personnel security awareness levels, fraud and social engineering control levels, computer and telecommunications networks, wireless devices, mobile devices, physical security access controls, security processes, and physical locations such as buildings, perimeters, and military bases.

The OSSTMM focuses on the technical details of exactly which items need to be tested, what to do before, during, and after a security test, and how to measure the results. New tests for international best practices, laws, regulations, and ethical concerns are regularly added and updated.

Provided here is the latest public release. To receive OSSTMM development status, notes, and betas, become part of the team. Subscribe now to join the ISECOM Gold or Silver Team or contact us at with how you can help OSSTMM development and earn a place on the core development team.

What do you think? Answer below!