Unit 4:Understand Cloud Software Assurance and Validation Flashcards

1
Q

What is ISO/IEC 27034-1?

A

This standard defines concepts, frameworks, and processes to help organizations integrate security within their Software Development Life Cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the ONF?

A

This is the Organizational Normative Framework. It consists of the following:
Business Context
Regulatory Context ( if the industry is regulated)
Technical Context
Specifications
Roles
Processes
Application Security Control. (ASC) library

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the ANF?

A

The ANF is the Application Normative Framework. This maintains the applicable portions of the ONF that are needed to enable a specific application to achieve a required level of security or the targeted level of trust.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ASMP?

A

This is the Application Security Management Process (ASMP) which results from both the ONF and ANF.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is involved in Application Security Testing?

A
  1. Static Application Security Testing (SAST)
  2. Dynamic Application Security Testing (DAST)
  3. Vulnerability assessments and Penetration Testing
  4. OWASP Recommendations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is are the differences between DAST vs SAST?

A

DAST is used for black-box testing. It is used when the applications are running.

SAST, is used for white box testing. This is used when the application is not running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does OWASP recommend for Active Security Testing?

A
  1. Configuration Management Testing
  2. Business Logic Testing
  3. Authentication Testing
  4. Authorization Testing
  5. Session management Testing
  6. Data Validation Testing
  7. Denial of Service Testing
  8. Web Services Testing
  9. Ajax Testing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly