Audience

The Security Tester certification is aimed at people who have some experience in security testing and wish to further develop their expertise in security testing.
To gain this certification, candidates must hold the Certified Tester Foundation Level certificate and not less than 3 (three) years of relevant academic, practical, or consulting experience. Please contact an ISTQB® Member Board or Exam Provider to determine the specific practical experience criteria.

 

    Content

    All examinations conducted at Advanced Level for this module are based on this Advanced Security Tester syllabus.

    • Chapter 1: Security Paradigms (135 minutes)
    • Chapter 2: Security Test Techniques (150 minutes)
    • Chapter 3: The Security Test Process(120 minutes)
    • Chapter 4: Standards and Best Practices (195 minutes)
    • Chapter5 : Adjusting To the Organizational Context (195 minutes)
    • Chapter 6 : Adjusting to Software Development Lifecycle Models(165 minutes)
    • Chapter 7: Security Testing as Part of an Information Security Management System (105 minutes)
    • Chapter 8: Reporting Test Results(135 minutes)
    • Chapter 9: Security Test Tools(90 minutes)

     

    Business Outcomes

    The Business Outcomes expected of a candidate who has achieved the Certified Tester Security Tester certification are as follows:

    • Plan, perform and evaluate security tests from a variety of perspectives – policy-based, risk-based, standards-based, requirements-based and vulnerability-based.
    • Align security test activities with project lifecycle activities.
    • Analyze the effective use of risk assessment techniques in a given situation to identify current and future security threats and assess their severity levels.
    • Evaluate the existing security test suite and identify any additional security tests.
    • Analyze a given set of security policies and procedures, along with security test results, to determine effectiveness.
    • For a given project scenario, identify security test objectives based on functionality, technology attributes and known vulnerabilities.
    • Analyze a given situation and determine which security testing approaches are most likely to succeed in that situation.
    • Identify areas where additional or enhanced security testing may be needed.
    • Evaluate effectiveness of security mechanisms.
    • Help the organization build information security awareness.
    • Demonstrate the attacker mentality by discovering key information about a target, performing actions on a test application in a protected environment that a malicious person would perform, and understand how evidence of the attack could be deleted.
    • Analyze a given interim security test status report to determine the level of accuracy, understandability, and stakeholder appropriateness.
    • Analyze and document security test needs to be addressed by one or more tools.
    • Analyze and select candidate security test tools for a given tool search based on specified needs.
    • Understand the benefits of using security testing standards and where to find them.

     

    Exam Mode

    • The exam is comprised of 45 multiple choice questions.
    • Total score: 80 points.Pass mark grade of 65% to be completed
    • 120 minutes test time. Participants that take the exam not in their spoken language, will receive additional 25% time, and will have 30 minutes more, or a total of 150 min.

     

    Video Introduction

    Scan the QR code below with WeChat to learn about the ISTQB® Certified Tester Security Tester :