Lesson 1 of 10 · Lesson + Lab · 75 min · Free preview

Security Testing for QA: CIA, STRIDE, OWASP Top 10, Ethics & Juice Shop Setup

Build the mental model a QA engineer needs for security work — the CIA triad, STRIDE threat modeling, the OWASP Top 10 2021, the legal/ethical rules you must follow, and a running Juice Shop lab.

Why this matters on the job

On most Indian service and product teams, security is not a separate team's problem any more. When a QA engineer signs off a release, they are implicitly saying "the obvious security requirements are met". A missed broken access control or an unescaped field that allows cross-site scripting can leak customer data and trigger a breach notification under India's data-protection rules. Interviewers at product companies increasingly ask QA candidates: "How would you verify that a user cannot see another user's invoice?" — that is a security test case, and it is now expected of functional testers, not just specialists.

This course teaches you to test like a QA engineer verifying security requirements and writing clear, reproducible bug reports — not like an attacker. Everything you do runs against your own machine.

Concepts

The CIA triad

Every security requirement maps to one of three properties. Use this to turn a vague worry into a testable requirement.

PropertyQuestion a tester asksExample test idea
ConfidentialityCan someone see data they should not?Does user A see user B's order?
IntegrityCan data be changed without authorisation?Can I change the price field in a basket request?
AvailabilityCan the service be made to stop?Does a huge input crash the endpoint?

STRIDE — a threat-modeling checklist

STRIDE gives you categories of threat so you do not stare at a blank page. For each feature, ask which apply.

LetterThreatViolates
SSpoofing (pretend to be someone)Authentication
TTampering (alter data)Integrity
RRepudiation (deny an action)Non-repudiation
IInformation disclosureConfidentiality
DDenial of serviceAvailability
EElevation of privilegeAuthorisation

OWASP Top 10 (2021)

The industry reference list of the most critical web risks. You will test for each of these across this course.

  1. A01 Broken Access Control
  2. A02 Cryptographic Failures
  3. A03 Injection (incl. XSS)
  4. A04 Insecure Design
  5. A05 Security Misconfiguration
  6. A06 Vulnerable & Outdated Components
  7. A07 Identification & Authentication Failures
  8. A08 Software & Data Integrity Failures
  9. A09 Security Logging & Monitoring Failures
  10. A10 Server-Side Request Forgery (SSRF)

Ethics and the law — read before you touch anything

Only test systems you own or have explicit written authorisation to test. In India, accessing or altering a computer system without permission is an offence under the Information Technology Act, 2000 — notably Section 43 (unauthorised access, civil liability) and Section 66 (hacking, criminal). Scanning or attacking a third-party website, your employer's production system without a signed scope, or any app that is not yours can expose you to real legal and disciplinary consequences, even "just to test". Every lab in this course runs against software on your own laptop (OWASP Juice Shop or similar deliberately vulnerable training apps). Never point these tools at a system that is not explicitly in scope.

Hands-on Lab: Install and launch OWASP Juice Shop locally

OWASP Juice Shop is an intentionally insecure web app built for security training. We will use it for the whole course. You need Docker installed (Docker Desktop).

  1. Confirm Docker works:
    docker --version
  2. Pull and run Juice Shop (this binds it only to your machine):
    docker run --rm -p 3000:3000 bkimminich/juice-shop
  3. Wait for the log line Server listening on port 3000.
  4. Open http://localhost:3000 in your browser. You should see the Juice Shop storefront. (Note: it is served over plain HTTP on localhost, which is fine for a local lab.)
  5. Register a throwaway account (Account → Login → "Not yet a customer?"). Use a fake email like tester@juice.local and a password you will reuse for labs.
  6. Click the small round "Score Board" hint — or navigate directly to http://localhost:3000/#/score-board. This board tracks challenges you solve and is your built-in progress tracker.
  7. Expected result: storefront loads, you are logged in, and the score board renders a grid of challenges.

To stop the app, press Ctrl+C in the terminal. Because we used --rm, the container is removed; your progress resets on restart, which is fine for learning.

Real-world assignment

Pick one real feature from any app you have tested at work (for example: "a user downloads their own invoice PDF"). Write a one-page mini threat model: list the feature, draw the data flow in words (browser → API → database), and for each STRIDE letter write one sentence on whether that threat applies and a test idea. This is exactly the artefact a security-aware QA produces in sprint planning.

Key takeaways

  • Security requirements map to Confidentiality, Integrity, Availability — use CIA to make worries testable.
  • STRIDE gives you six threat categories so threat modeling is a checklist, not guesswork.
  • The OWASP Top 10 2021 is your syllabus of web risks; this course walks through it hands-on.
  • Legal and ethical scope is non-negotiable: only test systems you own or are authorised to test (India's IT Act, 2000). All labs run against your local Juice Shop.

🧪 Practical checklist

Do each task yourself and tick it off. All tasks are required to complete this lesson.

🎤 Interview questions

What is the CIA triad and how does it help a tester?

Confidentiality, Integrity and Availability — the three core security properties. It lets a tester convert a vague security concern into a concrete, testable requirement by asking which property a feature must protect.

What is STRIDE used for?

STRIDE is a threat-modeling mnemonic (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege). It gives testers categories of threat to check against each feature so modeling is systematic.

Why must you only test systems you own or are authorised to test?

Unauthorised access or alteration of a computer system is illegal — in India under the Information Technology Act 2000 (e.g. Sections 43 and 66) — and breaches professional ethics. Authorised scope protects you legally and keeps testing responsible.

Why is OWASP Juice Shop a good practice target?

It is an intentionally vulnerable application designed for training, runs entirely on your own machine, and has a built-in score board, so you can practise safely and legally without touching anyone else's systems.

📝 Quiz, progress tracking & certificate

You're reading a free preview. Premium members tick off labs, take the quiz, unlock all 10 lessons and earn a verifiable certificate.

💎 Unlock with Premium Premium login
✓ You're subscribed! Job alerts arrive daily at 9 AM.
Scroll to Top