Chapter 6 of 812% of exam

Security Assessment and Testing

Domain 6 covers designing assessment and audit strategies, testing security controls, collecting security process data, reporting results and handling exceptions, and conducting internal, external and third-party audits.

Testing techniques

NIST groups technical assessment techniques into review techniques, which passively examine documentation, logs, rulesets and configurations; target identification and analysis, which discovers hosts, ports and potential vulnerabilities; and target vulnerability validation, which confirms them, for example by penetration testing.

Scan versus penetration test
Scanning identifies potential vulnerabilities; penetration testing tries to exploit them to confirm existence and impact.
NIST SP 800-115 §4–5
Four phases
Penetration testing can be viewed as planning, discovery, attack and reporting; no testing occurs in planning, where rules, approval and goals are set.
NIST SP 800-115 §5.2
Review techniques
Documentation, log, ruleset and configuration reviews examine systems passively.
NIST SP 800-115 §3

Security process data and logs

Beyond technical tests, assessors collect evidence that processes work: account management, backup verification, training, DR/BC testing and management review. Logs are only useful as evidence if they are complete, protected and time-consistent.

Backups are validated
Backups should be stored offsite, rotated and periodically validated.
NIST SP 800-34 Rev. 1
Time synchronization
Synchronize logging hosts' clocks to a common time source so events can be correlated.
NIST SP 800-92
Centralized logging
Use log management infrastructure with centralized log servers.
NIST SP 800-92

Reporting, remediation and exceptions

Findings are prioritized by risk, remediated or formally handled as exceptions, and sometimes disclosed to outside parties. Unfixable findings do not disappear; they are tracked and accepted by the accountable official.

Prioritize by risk
A fix is higher priority when it reduces risk more; low-risk flaws on a few low-importance assets rank lower.
NIST SP 800-40 Rev. 4
POA&M
Weaknesses not yet remediated are tracked in a plan of action and milestones, and residual risk is accepted by the authorizing official.
NIST SP 800-37 Rev. 2
Coordinated disclosure
Report vulnerabilities to the vendor and coordinate publication with remediation.
ISO/IEC 29147

Audits and assessors

Audits may be internal, external or third-party, and on-premises, cloud or hybrid. The value of an assessment depends on the assessor's independence and on what the report actually covers.

Assessor independence
Select control assessors for both technical expertise and the level of independence required.
NIST SP 800-37 Rev. 2 Task A-1
SOC 2 Type 1 versus Type 2
Type 1 addresses control design at a point in time; Type 2 adds operating effectiveness over a period.
AICPA SOC 2 guide
Server-side enforcement
Access control is only effective in trusted server-side code, so interfaces such as APIs are tested directly.
OWASP Top 10:2025 A01 Broken Access Control

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report