Owasp Testing Guide v4

Configuration and Deployment Management Testing

Understanding the deployed configuration of the server hosting the web application is almost as important as the application security testing itself. After all, an application chain is only as strong as its weakest link. Application platforms are wide and varied, but some key platform configuration errors can compromise the application in the same way an unsecured application can compromise the server.

In order to evaluate the readiness of the application platform, testing for configuration management includes the following sections: