ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

A security team is considering adopting the Open Source Security Testing Methodology Manual (OSSTMM) for their penetration testing activities. Which of the following is a key characteristic emphasized by OSSTMM that differentiates it from other methodologies?

  1. AIt focuses exclusively on automated vulnerability scanning tools.
  2. BIt strictly limits testing to application layer vulnerabilities.
  3. CIt is primarily designed for compliance auditing against regulatory frameworks.
  4. DIt provides a scientific, metric-based approach to security testing.
Show answer & explanation

Correct answer: D. It provides a scientific, metric-based approach to security testing.

OSSTMM is known for its scientific, metric-based approach to security testing, providing a detailed framework for measuring the security of operational technology, human security, and physical security, beyond just IT systems.

Why the other options are wrong

  • A. OSSTMM is comprehensive and includes manual testing, not just automated scanning.
  • B. OSSTMM covers a broad range of security aspects, including physical and human security, not just application layer.
  • C. While it can support compliance, its primary focus is on a comprehensive, measurable test.

OSSTMM (Open Source Security Testing Methodology Manual)

A peer-reviewed methodology for security testing that provides a scientific, repeatable, and metric-based approach to assess operational security, often focusing on the measurable impact of security controls.

  • Metric-based and scientific approach
  • Covers a wide range of security: physical, human, operational
  • Focuses on measurable impact and real-world results

Memory trick: PTES is steps, OWASP for web, OSSTMM for science.

More Security Assessment and Testing questions