How security testing works
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
Tiering suppliers, asking questions that produce information, reading audit reports and SBOMs, and contracting for what matters.
Most organisations have more exposure through suppliers than through their own infrastructure, and assess it with a questionnaire nobody reads carefully.
This course covers how to tier suppliers by what they can actually cost you, what to ask and what to ask for instead, how to read an audit report or an SBOM, and which contractual terms are worth negotiating.
4 lessons · 54 min
Four distinct kinds of third-party exposure, which need four different answers.
Scaling effort to exposure, and replacing yes-or-no forms with specifics and artefacts.
What each artefact actually certifies, and the pages that matter.
The clauses worth negotiating, what to watch during the relationship, and leaving without leaving data behind.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
2 min read
2 min read
2 min read
2 min read
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
A methodical way through an application: mapping, authentication flows, access control and business logic.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.