Skip to content

Security testing use cases

A test plan for the way your application works.

Choose a workflow, prepare the right accounts and define the evidence you need. These plans combine an authorized automated baseline with specific decisions about manual review.

12 practical security testing plans.

Each plan covers assets, roles, preparation, report evidence and the limits of automation. Choose by application architecture or the decision your team needs to make.

Choose the plan by the boundary you need to test.

Customer data boundaries

Use the SaaS, multi-tenant or authenticated plans when the question is who can access a customer's record, organization or privileged action.

Transactions and state changes

Use the ecommerce or fintech plan when permissions alone are insufficient and a payment, approval, cancellation or retry can change value.

Release and delivery decisions

Use the pre-launch, agency or release validation plan to tie a scoped assessment to a known deployment, repair owner and retest result.

A useful report says what was tested and where access or coverage was missing. These plans describe a testing approach; they do not imply industry certification or that every step is an automated MyPentest feature.