Meta tags:
Headings (most frequently used words):
qasec, com, software, security, testing, in, quality, assurance, and, development, site, updates, what, new, about,
Text of the page (most frequently used words):
the (16), #security (13), and (9), site (7), testing (7), software (6), #development (6), qasec (5), com (5), testers (4), this (4), for (4), implement (3), into (3), cycle (3), other (2), how (2), checking (2), that (2), you (2), see (2), penetration (2), production (2), has (2), just (2), quality (2), assurance (2), are (2), seeing (2), product (2), identifying (2), risks (2), reduce (2), about (2), new (2), changes (2), links (2), twitter (2), providing, help, since, 2005, contact, created, read, their, most, material, comes, from, world, post, review, although, unique, spin, relate, professional, someone, who, performed, both, duties, easy, alike, engineers, hackers, way, they, application, all, articles, meant, short, point, welcome, besides, traditional, errors, conforms, spec, out, requirements, works, important, eliminate, potential, vulnerabilities, before, goes, classifying, these, bugs, can, cost, repairing, well, public, exposure, now, live, work, progress, essentially, going, add, sections, documents, monthly, until, completed, below, list, latest, date, writing, test, cases, using, fuzzers, business, case, frameworks, setting, appropriate, defect, handling, expectations, tracking, understanding, related, defects, useful, data, points, shaping, your, sdlc, program, updates, what, sponsored, webappsec, org, cgisecurity, projects, secure, lifecycle, categories, home, navigation, skip, main, content, information,
Text of the page (random words):
qasec com software security in development qa and information security skip to main content qasec com software security testing in quality assurance and development navigation home links about categories development 3 qa 3 secure development lifecycle 4 security testing 4 my other projects cgisecurity com webappsec org twitter qasec on twitter sponsored links site updates what s new the site is now live this site is a work in progress and i m essentially going to add new sections documents to this site monthly until it s completed below is a list of the latest changes to the site changes by date tracking and understanding security related defects useful data points for shaping your sdlc program 1 11 11 setting the appropriate security defect handling expectations in development and qa 6 15 09 the business case for security frameworks 4 23 07 using fuzzers in software testing 2 2 07 writing security test cases 1 5 07 identifying risks in the development cycle 10 18 06 about qasec com welcome to qasec com besides traditional testing checking for errors seeing if the product conforms to the spec d out requirements and seeing that it just works it s important to implement security testing into the qa cycle to eliminate potential vulnerabilities before the product goes into production by identifying and classifying the risks of these security bugs you can reduce the cost of repairing it as well as reduce public exposure to it i ve created this site for other software testers to read up on how to implement security checking into their cycle most of the material that you ll see comes from the penetration testing world post production security review although has a unique spin to relate this to professional software testers as someone who has performed in both duties it is easy to see just how alike penetration testers quality assurance engineers and hackers are in the way they implement testing of an application all site articles are meant to be short and to the point contact providing security help to software testers since 2005
|