For the complete documentation index, see llms.txt. This page is also available as Markdown.

Application Security Testing - STO

Learn Security Testing Orchestration through Harness University

Seamlessly integrate security scanners and orchestrate tests anywhere across your build pipelines. Enable developers to rapidly remediate vulnerabilities through intelligent prioritization and deduplication.

Go to Harness University for the full catalogue of courses and certifications.

Self-Paced Training Instructor-Led Training Certifications

Self-Paced Training

Free self-paced courses that you can consume on your own time.

Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

Security Testing Orchestration - Developer

Security Testing Orchestration - Developer badge

Product version: Harness STO Free Plans

Assesses the fundamental skills to deploy your applications with STO projects.

Review Study Guide

Objective
Material

1. Introduction to Harness Security Testing Orchestration

Explain the importance of security testing in modern software development.

Describe the common issues in current security testing practices, including manual and standalone scanning, slow identification of vulnerabilities, siloed visibility, and inconsistent governance.

2. Setting up the Environment

Install and configure Harness Security Testing Orchestration on a local development environment.

Connect Harness Security Testing Orchestration to version control systems (e.g., Git) and CI/CD pipelines, emphasizing the integration aspect to address manual and standalone scanning.

3. Creating Test Plans

Create a basic security test plan using Harness Security Testing Orchestration.

Define test scenarios, including target applications, endpoints, and test inputs, with a focus on automation to eliminate delays.

4. Test Automation

Implement basic security tests, such as OWASP Top Ten vulnerabilities scanning, and automate them within CI/CD pipelines to address the issue of delayed identification of vulnerabilities.

Integrate third-party security testing tools into Harness Security Testing Orchestration to expand automated scanning capabilities.

5. Test Execution and Reporting

Execute security tests within a CI/CD pipeline as gate checks, ensuring that vulnerabilities are identified before release.

Analyze and interpret security test results and generate reports, promoting visibility into vulnerabilities throughout the development process.

6. Integration and Extensibility

Customize security testing workflows in Harness Security Testing Orchestration to align with specific release processes, addressing inconsistent governance.

Integrate additional security testing tools or plugins seamlessly to consolidate scanning efforts.

7. Security Best Practices

Apply security best practices to code and infrastructure within the CI/CD pipeline, ensuring that scans are integrated into the release process.

Implement security testing as an integral part of the software development lifecycle, avoiding siloed visibility.

8. Compliance and Regulations

Understand and adhere to relevant compliance standards (e.g., GDPR, HIPAA) in security testing.

Ensure that security testing processes align with regulatory requirements, emphasizing the importance of integration and governance.

9. Troubleshooting and Debugging

Identify and resolve common issues and errors in security testing, including problems related to integration and automation.

Debug integration problems between Harness Security Testing Orchestration and other tools to maintain a smooth CI/CD pipeline.

10. Performance Optimization

Optimize security testing processes for efficiency and speed within the CI/CD pipeline.

Implement caching and parallelization strategies for security tests to address the issue of speed and delays in vulnerability identification.

Register for Exam

Exam Details

The Security Testing Orchestration(STO) Developer exam tests your knowledge and skills of the Harness Security Testing Orchestration module.

Prerequisites

  • Basic terminal skills

  • Basic understanding of on-premise or cloud architecture

Exam Details

Exam Type
Duration

Knowledge Exam

90 minutes

Covered Domain
Coverage

Introduction to Harness Security Testing Orchestration

10%

Setting up the Environment

10%

Creating Test Plans

10%

Test Automation

15%

Test Execution and Reporting

15%

Integration and Extensibility

10%

Security Best Practices

10%

Compliance and Regulations

5%

Troubleshooting and Debugging

10%

Performance Optimization

5%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objective

1

Introduction to Harness Security Testing Orchestration

1.1

Explain the importance of security testing in modern software development.

1.2

Describe the common issues in current security testing practices, including manual and standalone scanning, slow identification of vulnerabilities, siloed visibility, and inconsistent governance.

2

Setting up the Environment

2.1

Install and configure Harness Security Testing Orchestration on a local development environment.

2.2

Connect Harness Security Testing Orchestration to version control systems (e.g., Git) and CI/CD pipelines, emphasizing the integration aspect to address manual and standalone scanning.

3

Creating Test Plans

3.1

Create a basic security test plan using Harness Security Testing Orchestration.

3.2

Define test scenarios, including target applications, endpoints, and test inputs, with a focus on automation to eliminate delays.

4

Test Automation

4.1

Implement basic security tests, such as OWASP Top Ten vulnerabilities scanning, and automate them within CI/CD pipelines to address the issue of delayed identification of vulnerabilities.

4.2

Integrate third-party security testing tools into Harness Security Testing Orchestration to expand automated scanning capabilities.

5

Test Execution and Reporting

5.1

Execute security tests within a CI/CD pipeline as gate checks, ensuring that vulnerabilities are identified before release.

5.2

Analyze and interpret security test results and generate reports, promoting visibility into vulnerabilities throughout the development process.

6

Integration and Extensibility

6.1

Customize security testing workflows in Harness Security Testing Orchestration to align with specific release processes, addressing inconsistent governance.

6.2

Integrate additional security testing tools or plugins seamlessly to consolidate scanning efforts.

7

Security Best Practices

7.1

Apply security best practices to code and infrastructure within the CI/CD pipeline, ensuring that scans are integrated into the release process.

7.2

Implement security testing as an integral part of the software development lifecycle, avoiding siloed visibility.

8

Compliance and Regulations

8.1

Understand and adhere to relevant compliance standards (e.g., GDPR, HIPAA) in security testing.

8.2

Ensure that security testing processes align with regulatory requirements, emphasizing the importance of integration and governance.

9

Troubleshooting and Debugging

9.1

Identify and resolve common issues and errors in security testing, including problems related to integration and automation.

9.2

Debug integration problems between Harness Security Testing Orchestration and other tools to maintain a smooth CI/CD pipeline.

10

Performance Optimization

10.1

Optimize security testing processes for efficiency and speed within the CI/CD pipeline.

10.2

Implement caching and parallelization strategies for security tests to address the issue of speed and delays in vulnerability identification.

Next Steps

The Security Testing Orchestration Developer exam can start immediately after registering. Please allow up to 90 mins to complete the knowledge exam.

  1. Create an account in Harness University

  2. Review the Study Guide above.

  3. Register for an exam.

  4. Take the exam.

Register for Exam

Security Testing Orchestration - Administrator

Security Testing Orchestration - Administrator badge

Product version: Harness STO Paid Plans

Assesses the fundamental skills to deploy and maintain STO Engineering projects and the overall Harness Platform. This exam builds upon the STO Developer Certification.

Review Study Guide

Topic
Material

1. Harness Security Testing Overview

Understand the core principles and concepts of Harness Security Testing Orchestration.

Explain the importance of security testing in the software development lifecycle.

Differentiate between various types of security testing (e.g., static analysis, dynamic analysis, penetration testing) and their relevance in Harness.

2. Setting Up Harness Security Testing Environment

Install and configure Harness Security Testing Orchestration in a lab or testing environment.

Integrate Harness with popular security testing tools and platforms.

Create and manage user accounts and permissions for Harness Security Testing.

3. Creating Security Testing Pipelines

Define security testing workflows within Harness, including pre-test and post-test actions.

Configure pipeline triggers and conditions for automated security testing.

Establish notification and alerting mechanisms for test results.

4. Managing Test Artifacts

Upload and manage security test artifacts, including source code, binaries, and test data.

Implement version control and artifact tagging strategies within Harness.

Optimize storage and resource utilization for test artifacts.

5. Automated Security Test Execution

Execute automated security tests using various testing tools and frameworks through Harness.

Schedule and orchestrate recurring security test runs.

Monitor and analyze test execution results and log data.

6. Security Test Reporting and Analysis

Generate comprehensive security test reports and dashboards.

Analyze test results to identify vulnerabilities and security issues.

Provide recommendations for remediation based on test findings.

7. Integration with CI/CD

Integrate Harness Security Testing into continuous integration and continuous deployment (CI/CD) pipelines.

Ensure seamless automation and feedback loops between development and security teams.

Implement version control and artifact tagging strategies within Harness.

8. Security Testing Best Practices

Demonstrate an understanding of industry best practices in security testing.

Apply secure coding principles and techniques to reduce vulnerabilities.

Stay updated with the latest security threats and vulnerabilities relevant to software development.

9. Security Compliance and Governance

Implement security compliance policies and standards within Harness Security Testing.

Ensure regulatory and industry-specific compliance (e.g., GDPR, HIPAA) in security testing processes.

Perform security risk assessments and provide recommendations for risk mitigation.

Register for Exam

Exam Details

The Security Testing Orchestration Administrator exam tests your knowledge and skills of the Harness Security Testing Orchestration module.

Prerequisites

Exam Details

Exam Type
Duration

Knowledge Exam

90 minutes

Hands On Exam

120 minutes

Covered Domain
% of Coverage

1. Harness Security Testing Overview

16%

2. Setting Up Harness Security Testing Environment

15%

3. Creating Security Testing Pipelines

14%

4. Managing Test Artifacts

11%

5. Automated Security Test Execution

13%

6. Security Test Reporting and Analysis

10%

7. Integration with CI/CD

9%

8. Security Testing Best Practices

6%

9. Security Compliance and Governance

6%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objective

1

Harness Security Testing Overview

1.1

Understand the core principles and concepts of Harness Security Testing Orchestration.

1.2

Explain the importance of security testing in the software development lifecycle.

1.3

Differentiate between various types of security testing (e.g., static analysis, dynamic analysis, penetration testing) and their relevance in Harness.

2

Setting Up Harness Security Testing Environment

2.1

Install and configure Harness Security Testing Orchestration in a lab or testing environment.

2.2

Integrate Harness with popular security testing tools and platforms.

2.3

Create and manage user accounts and permissions for Harness Security Testing.

3

Creating Security Testing Pipelines

3.1

Define security testing workflows within Harness, including pre-test and post-test actions.

3.2

Configure pipeline triggers and conditions for automated security testing.

3.3

Establish notification and alerting mechanisms for test results.

4

Managing Test Artifacts

4.1

Upload and manage security test artifacts, including source code, binaries, and test data.

4.2

Implement version control and artifact tagging strategies within Harness.

4.3

Optimize storage and resource utilization for test artifacts.

5

Automated Security Test Execution

5.1

Execute automated security tests using various testing tools and frameworks through Harness.

5.2

Schedule and orchestrate recurring security test runs.

5.3

Monitor and analyze test execution results and log data.

6

Security Test Reporting and Analysis

6.1

Generate comprehensive security test reports and dashboards.

6.2

Analyze test results to identify vulnerabilities and security issues.

6.3

Provide recommendations for remediation based on test findings.

7

Integration with CI/CD

7.1

Integrate Harness Security Testing into continuous integration and continuous deployment (CI/CD) pipelines.

7.2

Ensure seamless automation and feedback loops between development and security teams.

7.3

Implement version control and artifact tagging strategies within Harness.

8

Security Testing Best Practices

8.1

Demonstrate an understanding of industry best practices in security testing.

8.2

Apply secure coding principles and techniques to reduce vulnerabilities.

8.3

Stay updated with the latest security threats and vulnerabilities relevant to software development.

9

Security Compliance and Governance

9.1

Implement security compliance policies and standards within Harness Security Testing.

9.2

Ensure regulatory and industry-specific compliance (e.g., GDPR, HIPAA) in security testing processes.

9.3

Perform security risk assessments and provide recommendations for risk mitigation.

Next Steps

The Security Testing Orchestration Administrator exam can start immediately after registering. Please allow 90 mins for the knowledge exam and approximately 120 minutes for the hands on exam.

  1. Create an account in Harness University

  2. Register for an exam. There is a $50 fee for the exam

  3. Take the exams

    1. There will be a knowledge and hands on portion.

Register for Exam

Security Testing Orchestration - Architect (BETA COMING SOON)

Security Testing Orchestration - Architect (BETA COMING SOON) badge

Product version: Harness STO Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assess key technical job functions and advanced skills in design, implementation and management of STO.

Last updated

Was this helpful?