# Security Testing — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/l-testing

> SAST, DAST, SCA and pentests.

## Layers of automated and manual testing

**SAST** (static analysis, such as Semgrep or CodeQL) finds risky code patterns before running it. **SCA** finds vulnerable dependencies. **DAST** (dynamic testing, such as OWASP ZAP) probes a running application for issues like missing headers and injection. **Secret scanning** catches leaked credentials. Automated tests for authorisation rules catch access control regressions. Periodic **penetration tests** and bug bounty programmes find business-logic flaws automation misses. Test only systems you own or are authorised to test.

## Security as a habit

Testing, review, error handling and a checklist make security part of everyday engineering.

![Four ideas: security testing, exceptional conditions, code review, checklist.](assets/figures/owasp-top-10/section-8-map.svg) — Figure 8.1 — Testing, error handling, review and checklist.

## Security checks in a pipeline

An example stage list.

```text
on every pull request:
  - SAST (Semgrep / CodeQL) on changed code
  - dependency scan (npm audit / pip-audit / Trivy)
  - secret scan (gitleaks)
  - unit + authorisation tests (user A cannot read user B's data)
nightly / pre-release:
  - DAST baseline scan (OWASP ZAP) against staging
  - container image scan; IaC scan
periodically:
  - penetration test; threat model review for new features
```

## Triage findings, do not just collect them

Assign owners and deadlines by severity; a growing pile of ignored findings is a risk in itself.

**Quiz:** What does DAST test?

- [ ] Only passwords
- [ ] Source code without running it
- [ ] Only dependencies
- [x] A running application, from the outside

*Answer:* A running application, from the outside. Dynamic application security testing.
