Book online today or if you need any assistance or help
choosing the right course for you, please call our team on 08000 199337 and
we will help point you in the right direction.
With the ever-increasing numbers of security breaches, both human and machine-based, significantly more understanding is required from testers to ensure that the proper quality assurance measures are in place for assuring the security of IT systems.
Many courses about security testing concentrate solely on the very technical hacking side of things, which is great, but it is not the whole picture. This course is aimed at the softer-side of security testing and addresses the following key elements and how we manage them from a testing perspective through the life cycle from inception to delivery, including:
Lack of adequate defences and testing of the defences that are in place
Defective software in general
A limited view of security and testing
Placing too much trust in technology
Security is an afterthought in most development projects
Lack of awareness at the executive level. Everybody knows cybersecurity is a problem, but very few people know how to deal with the risks and challenges.
Who is the course for?
The ISTQB Advanced Security Tester Course is for Technical Testers, Security Testers, Security Co-ordinators and Managers, plus testers and test managers who are serious about including security aspects into their test plans or who want to specialise.
E-Learning Course
What’s Included?
Three months of unlimited access to the online course
A downloadable electronic copy of the complete set of course materials. No expiration to access. Digital rights management and intellectual property rights protections apply.
Sample exam questions throughout the course
ISTQB Advanced Security Tester Syllabus and the glossary of terms used in Software Testing produced by members of the ISTQB
Examples and exercises including solutions
Next Steps: Follow-on Courses After ISTQB Advanced Security Tester Course
After achieving the ISTQB Advanced Security Tester certification, you’re prepared to take the next step in your software testing career by exploring further modules within the Certified Tester Scheme.
Core Stream Modules
These modules are technology, methodology, and application domain-agnostic, building directly on the knowledge acquired at the Foundation Level.
Agile Stream
Tailored for those working in or transitioning to Agile environments, this stream emphasizes testing practices and principles within the Agile methodology.
Specialist Stream
For those looking to specialise further, this stream offers courses focusing on specific quality characteristics, test approaches, test activities, or industry-specific testing knowledge.
Holders of the ISTQB Advanced Security Tester certification are encouraged to explore these options to stay current with the latest practices and to enhance their professional development in the field of software testing and QA.
What are the benefits of the ISTQB Advanced Security Tester Qualification?
Security of our systems is a real big deal for us all, but how to test they are secure is a bit of a problem. Randy Rice security test expert will talk you through the Advanced Security Tester training course and the benefits it will bring:
Customer Review
“I thought ISTQB Advanced Security Tester was an excellent course that covered the syllabus well and in an interesting and engaging way. Having one of the authors of the ISTQB syllabus (Randall Rice) present the training content that he personally developed was a great bonus of course, and his enthusiasm for the topic was refreshing. The syllabus and course are a good bridge between the worlds of testing (as taught by ISTQB) and the technical world of penetration testing, without going in to the depths required by a pure security qualification like CISSP. I would certainly be looking to put other people through the course in the future”Chris Jones, Senior Managing Consultant, IBM
A Certificate at ISTQB Foundation level must have been awarded for candidates to sit this course
It is recommended that candidates have at least three-years testing experience before attempting the course and exam.
The Exam
To qualify as an internationally-recognized Certified Advanced Level Security Tester and be issued with an ISTQB® Advanced Level Certificate, delegates must successfully pass the exam administered by the relevant National Board or Examination Provider.
The 2-hour exam contains 45 questions, of which 60% must be answered correctly for a pass to and certificate to be awarded.
If English is not your first language, you can apply for an additional time.
TSG Training will issue Peaarson VUE exam voucher after the course and you can use this to sit your exam at a local test centre.
An exam consisting of 40 multiple choice questions is sat over an hour at the end of the course and (25% extra time is available for non-native speakers or those who primary business language is not English). Delegates are awarded a pass if they answer 65% of the questions correctly.
Course Objectives
This course is aimed at the softer-side of security testing and addresses the following key elements and how we manage them from a testing perspective through the life cycle from inception to delivery, including:
Human lapses
Malicious insiders
Malicious outsiders
Lack of adequate defenses and testing of the defenses that are in place
Defective software in general
A limited view of security and testing
Placing too much trust in technology
Security is an afterthought in most development projects
Lack of awareness at the executive level. Everybody knows cybersecurity is a problem, but very few people know how to deal with the risks and challenges.
ISTQB Security Tester Syllabus – Key points
Module 1 – The Basis of Security Testing
Security Risks
Information Security Policies and Procedures
Security Auditing and Its Role in Security Testing.
Module 2 – Security Testing Purposes, Goals and Strategies
Introduction
The Purpose of Security Testing
The Organizational Context
Security Testing Objectives
The Scope and Coverage of Security Testing Objectives.
Module 4 – Security Testing Throughout the Software Lifecycle
Role of Security Testing in a Software Lifecycle
The Role of Security Testing in Requirements
The Role of Security Testing in Design
The Role of Security Testing in Implementation Activities
The Role of Security Testing in System and Acceptance Test Activities
The Role of Security Testing in Maintenance.
Module 5 – Testing Security Mechanisms
System Hardening
Authentication and Authorization
Encryption
Firewalls and Network Zones
Intrusion Detection
Malware Scanning
Data Obfuscation
Training.
Module 6 – Human Factors in Security Testing
Understanding the Attackers
Social Engineering
Security Awareness.
Module 7 – Security Test Evaluation and Reporting
Security Test Evaluation
Security Test Reporting.
Module 8 – Security Testing Tools
Types and Purposes of Security Testing Tools
Tool Selection.
Module 9 – Standards and Industry Trends
Understanding Security Testing Standards
Applying Security Standards
Industry Trends.
FAQ’s
Who should take the ISTQB Advanced Security Tester course?
The course is designed for individuals with a serious interest in integrating security testing within their quality assurance process. This includes technical testers, security testers, security coordinators, security managers, as well as test managers who wish to understand or specialise in security testing.
What prerequisites are required for the ISTQB Advanced Security Tester course?
Candidates are expected to have an ISTQB Foundation Level certificate and at least three years of professional testing experience before enrolling in this Advanced course to ensure they can fully grasp the complex content covered.
What are the benefits of obtaining the ISTQB Advanced Security Tester Qualification?
Gaining this qualification will deepen your understanding of security testing within the software lifecycle, improve your ability to identify and mitigate security risks, and demonstrate a commitment to the field of security testing, therefore enhancing your professional credibility and career opportunities.
What is the format of the ISTQB Advanced Security Tester exam?
The exam lasts for two hours and consists of 45 multiple-choice questions. To pass, candidates must score at least 60%. For those who do not use English as their first language, or if it is not their primary business language, extra time may be requested. TSG Training offers the exam in the form of a Pearson VUE voucher or as a online proctor exam.
Does the course include practical exercises and real-world examples?
Yes, the ISTQB Advanced Security Tester course combines theoretical learning with practical exercises. Reviews indicate that instructors provide valuable information, practical examples, and real-life scenarios to help bridge the gap between theoretical knowledge and its real-world application.
25 reviews for ISTQB Certified Tester Security Tester (CT-SEC)
Rated 5 out of 5
Melissa Ellis| Tester| Capgemini –
Very informative, knowledgeable
Rated 5 out of 5
Bailey Clarke| SoftwareTester| Storefeeder –
John delievered the content great. Easy to understand the course content with it being delivered in digestable chunks with context and explanations alongside real life examples instead of just from slides.
Rated 4 out of 5
Lakshmi Pochampally | Test Lead | Capgemini –
Really good course. Very informative. Only downside is it could have been more interactive like doing some exam questions to promote discussion.
Rated 5 out of 5
miroslav melkner | test lead | solargis –
good explanations, nice examples, thumbs up
Rated 5 out of 5
Dukhbhanjan Jutla | Assoc. Delivery Director – QAT | NTT DATA –
Informative with lots of useful information and examples derived from previous projects
Online Exams The remote web proctor solution allows you to take your exams online, using a webcam, microphone and a stable internet connection. You can schedule your exam in advance, at a date and time of your choice. At the agreed time you will connect with a proctor who will invigilate your exam live. View More info here https://tinyurl.com/mr22kry9
A Pearson VUE exam voucher A pearson VUE exam voucher enables you to book and sit your exam at your local Pearson VUE testing centre at a time and date convenient to you. Pearson VUE centres are worldwide, and you will be able to choose the closest testing centre to you. View More info here https://tinyurl.com/2mhn5ust
E-learning is s training, learning, or education delivered online through a computer or any other digital device, where you can work through the course at your own pace.
If you are attending a classroom course, then this will be taken at our many training centres within the UK. Our London location is Minories London EC3N 1BJ
Virtual classroom is like being in a classroom where students gather, except you will be in your home, office, or other place of your choice.
Pass Protect, offered by TSG Training, is a valuable option for those concerned about the possibility of not passing their exam on the first attempt. It acts like an insurance policy, allowing you to resit your exam at a significantly reduced rate. Pass Protect covers one resit per exam purchased, so you don’t have to worry about the cost of an additional attempt if you don’t pass initially.
Melissa Ellis| Tester| Capgemini –
Very informative, knowledgeable
Bailey Clarke| SoftwareTester| Storefeeder –
John delievered the content great. Easy to understand the course content with it being delivered in digestable chunks with context and explanations alongside real life examples instead of just from slides.
Lakshmi Pochampally | Test Lead | Capgemini –
Really good course. Very informative. Only downside is it could have been more interactive like doing some exam questions to promote discussion.
miroslav melkner | test lead | solargis –
good explanations, nice examples, thumbs up
Dukhbhanjan Jutla | Assoc. Delivery Director – QAT | NTT DATA –
Informative with lots of useful information and examples derived from previous projects