Why this matters on the job
On most Indian service and product teams, security is not a separate team's problem any more. When a QA engineer signs off a release, they are implicitly saying "the obvious security requirements are met". A missed broken access control or an unescaped field that allows cross-site scripting can leak customer data and trigger a breach notification under India's data-protection rules. Interviewers at product companies increasingly ask QA candidates: "How would you verify that a user cannot see another user's invoice?" — that is a security test case, and it is now expected of functional testers, not just specialists.
This course teaches you to test like a QA engineer verifying security requirements and writing clear, reproducible bug reports — not like an attacker. Everything you do runs against your own machine.
Concepts
The CIA triad
Every security requirement maps to one of three properties. Use this to turn a vague worry into a testable requirement.
| Property | Question a tester asks | Example test idea |
|---|---|---|
| Confidentiality | Can someone see data they should not? | Does user A see user B's order? |
| Integrity | Can data be changed without authorisation? | Can I change the price field in a basket request? |
| Availability | Can the service be made to stop? | Does a huge input crash the endpoint? |
STRIDE — a threat-modeling checklist
STRIDE gives you categories of threat so you do not stare at a blank page. For each feature, ask which apply.
| Letter | Threat | Violates |
|---|---|---|
| S | Spoofing (pretend to be someone) | Authentication |
| T | Tampering (alter data) | Integrity |
| R | Repudiation (deny an action) | Non-repudiation |
| I | Information disclosure | Confidentiality |
| D | Denial of service | Availability |
| E | Elevation of privilege | Authorisation |
OWASP Top 10 (2021)
The industry reference list of the most critical web risks. You will test for each of these across this course.
- A01 Broken Access Control
- A02 Cryptographic Failures
- A03 Injection (incl. XSS)
- A04 Insecure Design
- A05 Security Misconfiguration
- A06 Vulnerable & Outdated Components
- A07 Identification & Authentication Failures
- A08 Software & Data Integrity Failures
- A09 Security Logging & Monitoring Failures
- A10 Server-Side Request Forgery (SSRF)
Ethics and the law — read before you touch anything
Only test systems you own or have explicit written authorisation to test. In India, accessing or altering a computer system without permission is an offence under the Information Technology Act, 2000 — notably Section 43 (unauthorised access, civil liability) and Section 66 (hacking, criminal). Scanning or attacking a third-party website, your employer's production system without a signed scope, or any app that is not yours can expose you to real legal and disciplinary consequences, even "just to test". Every lab in this course runs against software on your own laptop (OWASP Juice Shop or similar deliberately vulnerable training apps). Never point these tools at a system that is not explicitly in scope.
Hands-on Lab: Install and launch OWASP Juice Shop locally
OWASP Juice Shop is an intentionally insecure web app built for security training. We will use it for the whole course. You need Docker installed (Docker Desktop).
- Confirm Docker works:
docker --version - Pull and run Juice Shop (this binds it only to your machine):
docker run --rm -p 3000:3000 bkimminich/juice-shop - Wait for the log line
Server listening on port 3000. - Open
http://localhost:3000in your browser. You should see the Juice Shop storefront. (Note: it is served over plain HTTP on localhost, which is fine for a local lab.) - Register a throwaway account (Account → Login → "Not yet a customer?"). Use a fake email like
tester@juice.localand a password you will reuse for labs. - Click the small round "Score Board" hint — or navigate directly to
http://localhost:3000/#/score-board. This board tracks challenges you solve and is your built-in progress tracker. - Expected result: storefront loads, you are logged in, and the score board renders a grid of challenges.
To stop the app, press Ctrl+C in the terminal. Because we used --rm, the container is removed; your progress resets on restart, which is fine for learning.
Real-world assignment
Pick one real feature from any app you have tested at work (for example: "a user downloads their own invoice PDF"). Write a one-page mini threat model: list the feature, draw the data flow in words (browser → API → database), and for each STRIDE letter write one sentence on whether that threat applies and a test idea. This is exactly the artefact a security-aware QA produces in sprint planning.
Key takeaways
- Security requirements map to Confidentiality, Integrity, Availability — use CIA to make worries testable.
- STRIDE gives you six threat categories so threat modeling is a checklist, not guesswork.
- The OWASP Top 10 2021 is your syllabus of web risks; this course walks through it hands-on.
- Legal and ethical scope is non-negotiable: only test systems you own or are authorised to test (India's IT Act, 2000). All labs run against your local Juice Shop.