AIS-05 Automated Application Security Testing
Test applications for security before release against defined acceptance criteria covering new systems, upgrades and versions, automating the testing where the delivery pipeline allows.
4
artefacts
1
held by a system
2
at each review
moderate
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Pipeline configuration showing automated security tests · Source control / CI pipeline
periodic reviewEvidence produced at each review
- Test results for recent releases, upgrades and new versions · Source control / CI pipeline
- Records of releases blocked or accepted against the criteria · Document repository
governing documentDocuments that govern the control
- The documented testing strategy with acceptance criteria for release · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Source control / CI pipeline); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Acceptance criteria undefined, so a failing result does not stop a release
- Upgrades and minor versions exempted from testing
- Automated tests present but their failures are routinely overridden
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAIS-04 Secure Application Design and Development · AIS-06 Automated Secure Application Deployment