Security tests verify that a control is functioning properly. These tests include *automated scans, tool-assisted penetration tests, and manual attempts* to undermine security. Security tests should take place on regular schedule, with attention paid to each of the key security controls. During review, the following factors should be taken into consideration:
- Availability of security testing resources
- Criticality of the systems and applications protected by the tested controls
* Sensitivity of information contained on tested systems and applications.
* Likelihood of a technical failure of the mechanism implementing the control
* Likelihood of a misconfiguration of the control that would jeopardise security
* Risk that the system will come under attack
* Rate of change of the control configuration
* Other changes in the technical environment that may affect the control performance
* Difficulty and time required to perform a control test
* Impact of the test on normal business operations
After assessing each of these factors, security teams *design and validate a comprehensive assessment* and testing strategy. This strategy may include frequent automated tests supplemented by infrequent manual tests.