Security/InfoSec/Test Driven Security: Difference between revisions

Jump to navigation Jump to search
No edit summary
Line 20: Line 20:
Security tests, also called compliance checks, verify that the configuration of a system matches the requirements of a security assurance level. A simple test would be to verify that SSH root login is disabled, which can be expressed into a MIG Action using the following JSON:
Security tests, also called compliance checks, verify that the configuration of a system matches the requirements of a security assurance level. A simple test would be to verify that SSH root login is disabled, which can be expressed into a MIG Action using the following JSON:


<source lang="json">
<source lang="javascript">
{
{
     "name": "compliance check for openssh",
     "name": "compliance check for openssh",
Confirmed users
529

edits

Navigation menu