How security testing works
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
Writing risks people can act on, scoring them honestly, and turning a register into decisions with owners and dates.
Risk assessment is where most security programmes either earn their budget or lose their audience. Done badly it produces a spreadsheet of nouns scored out of twenty-five. Done well it produces a short list of decisions somebody has actually made.
This course covers how to write a risk, how to score it without inventing precision, how treatment decisions get made and recorded, and how to present risk to people who have to choose between it and everything else.
4 lessons · 53 min
A cause, an event and a consequence — not a one-word category.
Likelihood and impact as an argument, not an arithmetic result.
Four possible endings, each with an owner, a date and somebody who signed.
What leadership needs, what to leave out, and how to show change over time.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
2 min read
2 min read
2 min read
2 min read
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
A methodical way through an application: mapping, authentication flows, access control and business logic.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.