Security 12-minute Test Plans

Back to schedule

Overview

Good software testing is about two things: depth and coverage. A shallow test won't really get into what the user will use the system for, and poor coverage means functionality goes untested.

The best way to get depth and coverage in testing is to have a plan. This is especially true about security testing. Without a plan, you end up wandering aimlessly.

In this activity, we will be creating 12-minute test plans. We will practice the art of sketching a quick testing plan for security in very limited span of time You will need to:

Activity

This activity is for groups of 4-6.

  1. Create a GoogleDoc called 12-minute Test Plans and share it with the instructor, and everyone at your table.
  2. Make sure everyone at your table is logged in and has the GoogleDoc open. You will all be editing at the same time in this exercise.
  3. Create some empty space on the GoogleDoc so that everyone has a space to edit. (Let's not crash GoogleDoc's conflict resolution algorithm.)
  4. Notify your instructor that you're ready. This activity is synchronized across the whole class
  5. Your instructor will give you a the name of a popular software system that you will be writing a test plan for.
  6. For the next 12 minutes, you will be making a test plan. Here's how it breaks down:
  7. Discuss as a group:
  8. Designate someone to briefly discuss your plan with the class.
  9. Get ready to do this again on a new system. We will continue to repeat this as time allows.

Submission & Grading

This activity is worth 10 points, and your grade is based on in-class participation. Nothing is due beyond class today, as long as you are participating and are reasonably close to completion. Your instructor will check your GoogleDoc before the end of class.