| 1 |
SAST |
Strong |
Every code change |
Pipeline results, supported |
Identifies coding flaws, insecure patterns and implementation weaknesses in source code. |
Very High |
Mature tools with deterministic execution and immediate developer feedback. |
Commit / Pull Request |
| 2 |
SCA / SBOM |
Strong |
Build + regular monitoring |
SBOM, vulnerability records, supported |
Detects vulnerable dependencies, license issues and component supply-chain risks. |
Very High |
Fully automatable through build integration and continuous monitoring. |
Build + Continuous Monitoring |
| 3 |
Component / API Testing |
Partial |
After successful Stage 1 |
Coverage and test results, partial |
Verifies service contracts, interfaces, business logic and API behavior. |
High |
Easily automated when interfaces are stable and testable. |
CI / Integration |
| 4 |
IAST |
Decision Needed |
Not defined |
Scope, tool and owner to confirm |
Runtime analysis during test execution to identify security weaknesses with application context. |
High |
Generally automated once tooling and deployment model are established. |
Integration / Pre-production |
| 5 |
DAST / Runtime Scan (ASVS 5) |
Gap / Partial |
Nightly / Release Target |
Scan report, owner to confirm |
Detects externally observable vulnerabilities in deployed applications. |
High |
Automated scanning is straightforward, but tuning and triage require human involvement. |
Nightly / Release Validation |
| 6 |
DAST - Destructive Pen Test |
Gap |
Release / Major Change |
Security assessment report |
Validates resilience against aggressive attack scenarios that may disrupt service. |
Low |
Requires controlled environments, expert judgment and risk management. |
Pre-release / Special Campaign |
| 7 |
Performance / Load / Fuzz Testing |
Gap |
Nightly + Daily Target |
Trend analysis, thresholds, owner to confirm |
Measures scalability, robustness and resistance to malformed inputs. |
High |
Modern load and fuzz frameworks automate execution and trending effectively. |
Nightly / Continuous Validation |
| 8 |
Integration / Regression Testing |
Gap / Partial |
Daily + SIT |
Test suite results, shared ownership |
Verifies system interactions and prevents previously corrected defects from reappearing. |
Very High |
Core CI/CD practice with strong automation support. |
CI / SIT |
| 9 |
Operational Vulnerability Scan |
Gap / Partial |
Regular Operations |
Rapid7 / OBOM Scanning? |
Assesses deployed environments, hosts, middleware and infrastructure exposure. |
High |
Scanning can be fully automated, remediation remains operationally driven. |
Operational / Continuous Monitoring |
| 10 |
FAT / SAT |
Partial |
Per Project / On-site |
Project package, scope to confirm |
Confirms contractual and operational acceptance criteria before handover. |
Low-Medium |
Some execution can be automated, but customer validation is largely manual. |
Project Gate |
| 11 |
Hardening Benchmark |
Partial |
Release (& Operational?) |
Benchmark reports |
Validates compliance with secure configuration standards and baselines. |
High |
CIS, DISA STIG and platform baseline checks are highly automatable. |
Release + Operations |