ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium
A security team is considering adopting the Open Source Security Testing Methodology Manual (OSSTMM) for their penetration testing activities. Which of the following is a key characteristic emphasized by OSSTMM that differentiates it from other methodologies?
- AIt focuses exclusively on automated vulnerability scanning tools.
- BIt strictly limits testing to application layer vulnerabilities.
- CIt is primarily designed for compliance auditing against regulatory frameworks.
- DIt provides a scientific, metric-based approach to security testing.
Show answer & explanationAnswer & explanation
Correct answer: D. It provides a scientific, metric-based approach to security testing.
OSSTMM is known for its scientific, metric-based approach to security testing, providing a detailed framework for measuring the security of operational technology, human security, and physical security, beyond just IT systems.
Why the other options are wrong
- A. OSSTMM is comprehensive and includes manual testing, not just automated scanning.
- B. OSSTMM covers a broad range of security aspects, including physical and human security, not just application layer.
- C. While it can support compliance, its primary focus is on a comprehensive, measurable test.
OSSTMM (Open Source Security Testing Methodology Manual)
A peer-reviewed methodology for security testing that provides a scientific, repeatable, and metric-based approach to assess operational security, often focusing on the measurable impact of security controls.
- Metric-based and scientific approach
- Covers a wide range of security: physical, human, operational
- Focuses on measurable impact and real-world results
Memory trick: PTES is steps, OWASP for web, OSSTMM for science.