Skip to content

ISTQB Certified Tester
Security Tester (CT-SEC)

Official logo for the ISTQB Certified Tester Security Tester certification.

Security is a critical part of software quality. As cyber threats become more sophisticated, organisations need testing professionals who can identify security risks, evaluate security mechanisms and support secure software delivery. The ISTQB® Certified Tester – Security Tester (CT-SEC) certification equips experienced testing professionals with the knowledge needed to plan, perform and evaluate security testing activities.

This certification focuses on security testing from multiple perspectives, including risk, requirements, vulnerabilities, standards, policies and human factors. It covers security testing processes, security mechanisms, security testing tools, reporting, standards and the role of security testing throughout the Software Development Lifecycle.

Whether you are involved in software testing, security testing, quality assurance or secure software development, CT-SEC provides internationally recognised guidance for improving security testing practices and supporting better protection of software systems.

 

ISTQB® Certified Tester – Security Tester (CT-SEC)
The Basis of Security Testing
Security Risk
Information Security Policies and Procedures
Security Auditing and its Role in Security Testing
Security Testing Purpose, Goals and Strategies
Introduction
The Purpose of Security Testing
The Organizational Context
Security Testing Objectives
The Scope and Coverage of Security Testing Objectives
Security Testing Approaches
Improving the Security Testing Practices
Security Testing Processes
Security Test Process Definition
Security Test Planning
Security Test Design
Security Test Execution
Security Test Evaluation
Security Test Maintenance
Security Testing Throughout the Software Lifecycle
The Role of Security Testing in a Software Lifecycle
The Role of Security Testing in Requirements
The Role of Security Testing in Design
The Role of Security Testing in Implementation Activities
The Role of Security Testing in System and Acceptance Test Activities
The Role of Security Testing in Maintenance
Testing Security Mechanisms
System Hardening
Authentication and Authorization
Encryption
Firewalls and Network Zones
Intrusion Detection
Malware Scanning
Data Obfuscation
Training
Human Factors in Security Testing
Understanding the Attackers
Social Engineering
Security Awareness
Security Test Evaluation and Reporting
Security Test Evaluation
Security Test Reporting
Security Testing Tools
Types and Purposes of Security Testing Tools
Tool Selection
Standards and Industry Trends
Understanding Security Testing Standards
Applying Security Standards
Industry Trends

Exam Structure

Candidates qualify for extra time if they are not writing the exam in their native language. Extra time needs to be applied for upon completing the exam registration form. 

No. of Questions: 45
Duration: 120 Min
Pass Mark: 65%
Extra Time (Non-Native Language): 30 Min
Lifetime Validity
Prerequisite: ISTQB Foundation (CTFL)

Exam Price

R  2 900

Why Get ISTQB CT-SEC Certified?

Security vulnerabilities can lead to data breaches, reputational damage, compliance issues and serious business risk. Organisations need skilled professionals who understand how to test systems from a security perspective and communicate findings effectively.

By earning the ISTQB Certified Tester – Security Tester certification, you will be able to:

Understand the principles and objectives of security testing
Plan, design, execute and evaluate security tests
Identify security risks, threats and vulnerabilities
Align security testing with software lifecycle activities
Evaluate security mechanisms such as authentication, authorisation and encryption
Understand human factors in security testing, including social engineering and security awareness
Analyse security test results and report findings to stakeholders
Select suitable security testing tools
Apply security testing standards and industry best practices
Demonstrate internationally recognised expertise in security testing

The certification is vendor-neutral and can be applied across different industries, technologies, tools and software development environments.

Who Is the ISTQB CT-SEC Certification For?

The ISTQB CT-SEC certification is designed for professionals who already have experience in security testing and want to further develop their expertise.

This certification is ideal for:

Software Testers
Security Testers
Test Analysts
Technical Test Analysts
Test Engineers
Test Managers
QA Engineers
Security Analysts
Test Consultants
Software Developers
Security Engineers
Quality Assurance Professionals
IT Risk Professionals
Information Security Professionals
Compliance and Audit Professionals involved in software quality or security
xxx

Ideal for professionals who need to understand software testing in safety-critical automotive environments.

Download Documents

Download the documents below for more information about the syllabus, exam structure, and sample exam questions for the ISTQB Certified Tester – Security Tester (CT-SEC) certification.

Please note that these documents are intended for informational purposes only and should not be considered official study material. For effective exam preparation, SASTQB recommends using accredited training course material and attending an accredited training course.

Official logo for the ISTQB Certified Tester Security Tester certification.

FAQ’s About ISTQB Security Tester (CT-SEC)

Q: What is the ISTQB Certified Tester – Security Tester (CT-SEC) certification?

The ISTQB CT-SEC certification is an internationally recognised Advanced Level Specialist certification that focuses on planning, performing and evaluating security testing. It covers security risks, vulnerabilities, security mechanisms, security testing processes, tools, standards and human factors.

Q: Who should take the CT-SEC certification?

The certification is suitable for experienced testers, security testers, test analysts, technical test analysts, test engineers, test managers, QA professionals, software developers, security analysts and professionals involved in security testing or secure software delivery.

Q: What are the prerequisites for the CT-SEC exam?

Candidates must hold a valid ISTQB Certified Tester Foundation Level certificate and should have at least three years of relevant academic, practical or consulting experience.

Q: Does CT-SEC cover security testing tools?

Yes. The CT-SEC syllabus covers types and purposes of security testing tools, tool selection and how to analyse security testing needs that may be supported by one or more tools.

Q: Is the CT-SEC certification tool-specific?

No. The ISTQB Security Tester certification is vendor-neutral. It focuses on security testing principles, techniques, standards and tool selection criteria rather than training candidates on one specific tool.

Q: Does CT-SEC cover ethical hacking?

CT-SEC includes concepts related to attacker mentality, vulnerabilities and protected test environments. However, it is a security testing certification, not an ethical hacking or penetration testing course. The focus is on structured security testing within software quality and risk management.

Q: What security mechanisms are covered in CT-SEC?

The syllabus includes security mechanisms such as system hardening, authentication, authorisation, encryption, firewalls, network zones, intrusion detection, malware scanning and data obfuscation.

Q: Is the CT-SEC certification recognised internationally?

Yes. Like all ISTQB certifications, CT-SEC is internationally recognised and demonstrates specialist knowledge in software security testing.

Q: Can I study on my own?

Yes. Candidates may prepare through self-study using the official ISTQB syllabus and recommended references. However, SASTQB recommends attending training through an ISTQB Accredited Training Provider for comprehensive, syllabus-aligned preparation.

Q: What certification should I take after CT-SEC?

After earning the ISTQB Certified Tester – Security Tester certification, you can continue your ISTQB certification journey with other Advanced Level, Specialist, Agile or Expert Level certifications, depending on your career goals.