OWASP - The Testing framework Phases Flashcards
Phase 1:
Before development begins – This phase focuses on defining the SDLC, revieing policies and standards, and developing measurement and metrics criteria for the project and ensure traceability.
Phase 2:
During definition and design – This phase focuses on reviewing security requirements, reviewing design and architecture, creating and reviewing Unified Modeling Language (UML) models, and creating and reviewing threat models.
Phase 3:
During development – This phase focuses on code walkthrough and code reviews.
Phase 4:
During deployment – This phase focuses on application penetration testing and configuration management testing.
Phase 5:
Maintenance and Operations – This phase focuses on conducting operational management reviews, conducting periodic health checks, and ensuring change verification.