ISTQB Mock App

Security

Security is the degree to which a system protects information and resources against unauthorized access, disclosure, modification, destruction, or disruption.

Official definition
ISTQB Official Glossary Definition
The degree to which a component or system protects its data and resources against unauthorized access or use and secures unobstructed access and use for its legitimate users.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Security?

Software security preserves confidentiality, integrity, availability, authenticity, and accountability through technical and organizational controls.

Protection focus: Prevents unauthorized actions.

Risk reduction: Security controls minimize threats and vulnerabilities.

Quality characteristic: Defined in ISO/IEC 25010.

Real World Example

An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.

The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Security points testing toward that hostile or risky behavior.

The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.

The team strengthens the controls because Security helps them test the product from the perspective of misuse, not only normal customer journeys.

Practice Questions

Question 1

Which statement BEST describes Security in the context of ISTQB terminology?

Question 2

A tester needs to explain Security to a non‑technical stakeholder. Which approach is MOST appropriate?

Test your knowledge with real ISTQB-style questions

You’ve learned Security. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams