Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Dr Jason Edwards and Dr. Jason Edwards. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dr Jason Edwards and Dr. Jason Edwards or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 110: Open Source Security Testing Methodology Manual (OSSTMM)

13:58
 
Share
 

Manage episode 494503755 series 3677570
Content provided by Dr Jason Edwards and Dr. Jason Edwards. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dr Jason Edwards and Dr. Jason Edwards or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

The OSSTMM is often overlooked—but it provides a rigorous, standards-based approach to security testing that aligns with the goals of CySA+ and many compliance frameworks. In this episode, we explain what the Open Source Security Testing Methodology Manual is, why it matters, and how it provides structure to everything from reconnaissance and vulnerability validation to operational control assessment and human interaction testing.

You’ll hear how OSSTMM complements tools and frameworks you already know, and how it fits into risk management, gap analysis, and audit preparation workflows. While not as widely adopted as MITRE or OWASP, OSSTMM is still a valuable lens through which to view incident preparedness and testing scope. If you’re aiming to round out your exam prep or develop a more mature understanding of testing methodologies, this episode belongs in your knowledge base. Brought to you by BareMetalCyber.com

  continue reading

130 episodes

Artwork
iconShare
 
Manage episode 494503755 series 3677570
Content provided by Dr Jason Edwards and Dr. Jason Edwards. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dr Jason Edwards and Dr. Jason Edwards or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

The OSSTMM is often overlooked—but it provides a rigorous, standards-based approach to security testing that aligns with the goals of CySA+ and many compliance frameworks. In this episode, we explain what the Open Source Security Testing Methodology Manual is, why it matters, and how it provides structure to everything from reconnaissance and vulnerability validation to operational control assessment and human interaction testing.

You’ll hear how OSSTMM complements tools and frameworks you already know, and how it fits into risk management, gap analysis, and audit preparation workflows. While not as widely adopted as MITRE or OWASP, OSSTMM is still a valuable lens through which to view incident preparedness and testing scope. If you’re aiming to round out your exam prep or develop a more mature understanding of testing methodologies, this episode belongs in your knowledge base. Brought to you by BareMetalCyber.com

  continue reading

130 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play