Cs Web Application Security Test PDF
Cs Web Application Security Test PDF
com
[email protected]
Tel.: +31 (0)70 310 13 40
Loire 128-A
2491 AJ The Hague
The Netherlands
About
Certified Secure exists to encourage and fulfill the growing interest in IT security knowledge and
skills. We stand for openness, transparency and the sharing of knowledge; making sure
everybody can experience and enjoy IT security. Security is serious fun!
All Certified Secure certifications, products and training are developed by IT security
professionals with international recognized expertise. Our involvement in the IT security
community worldwide, ensures relevant and high-quality standards. Delivering a wide variety of
online challenges, videos, tools and more, Certified Secure is the authoritative source for
practical IT security know-how.
Scope
This checklist can be used as a standard when performing a remote security test on a web
application. For developers and auditors a separate Web Application Secure Development
Checklist is available from https://www.certifiedsecure.com/checklists.
Usage
Security testers should use this checklist when performing a remote security test of a web
application. A risk analysis for the web application should be performed before starting with the
checklist. Every test on the checklist should be completed or explicitly marked as being not
applicable. Once a test is completed the checklist should be updated with the appropriate result
icon and a document cross-reference.
The completed checklist should never be delivered standalone but should be incorporated in a
report detailing the risk analysis and checklist results and the scope and context of the
performed remote security test.
License
This work is licensed under a Creative Commons Attribution No Derivatives 4.0 International
License. The complete Creative Commons license text can be found online at
https://creativecommons.org/licenses/by-nd/4.0/legalcode
Icon Explanation
Page 2 of 7
1.0 Deployment
1.5 Test the server using the Server Security Test Checklist
3.2 Test for unencrypted sensitive information stored at the client side
Page 3 of 7
3.7 Test for non SSL/TLS pages on sites processing sensitive information
Page 4 of 7
Page 5 of 7
7.0 Sessions
7.6 Test for missing revocation of other sessions when changing credentials
Page 6 of 7
9.0 Content
11.0 Miscellaneous
Page 7 of 7