Skip to content

Latest commit

 

History

History
33 lines (18 loc) · 3.02 KB

TEST-003-Interactive-Application-Securit-Testing-IAST.md

File metadata and controls

33 lines (18 loc) · 3.02 KB

Interactive Application Security Testing (IAST)

ID
DSOVS-TEST-003

Summary

IAST (Interactive Application Security Testing) is an important part of DevSecOps because it provides real-time security monitoring and analysis of web applications.

By integrating IAST into the development process, developers and security teams can identify and address application security vulnerabilities quickly and efficiently.

It helps to identify vulnerabilities earlier in the development cycle and provides testing for both known and unknown vulnerabilities across the entire application stack.

IAST also helps to prioritize and resolve application security issues by providing detailed vulnerability reports.

Level 0 - No tool to perform interactive application security testing

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 1 - Verify use of tool to perform on-demand scan to identify insecure code when the running application is being functionally tested

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 2 - Verify the implementation of the interactive application security testing tool into the build pipeline to perform automated scans and report status to the build

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

Level 3 - Verify that the findings are automatically recorded to a centralised issue tracker system and periodically review tool's effectiveness

lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum

References