Develop security testing strategy and plan
The testing strategy defines objectives, scope, methods, environments, roles, evidence, entry and exit criteria, defect handling, and release decision support.
Example: The test program owner should make testing risk-based and traceable to requirements, architecture, implementation, and misuse cases, with the testing depth and evidence justified for the release assurance plan.
Counterexample: The test program owner should treat a list of tools as a testing strategy. | The test program owner should apply identical depth despite different exposure and impact. | The test program owner should set completion criteria after seeing the results while assessing release assurance strategy.
Limitations: A list of tools is not a testing strategy.
Tradeoffs: Testing should be risk-based and traceable to requirements, architecture, implementation, and misuse cases.