LMNTRIX will start by becoming familiar with the application, to include reviewing provided documentation, holding meetings with Customer personnel familiar with the application, and/or requesting a demonstration. LMNTRIX will develop knowledge about how the application functions under normal conditions, including normal inputs and associated outputs. LMNTRIX will then assess the application’s response to various inputs and conditions using appropriate security testing tools.
Within the parameters of the agreed-upon scope, LMNTRIX will test the application as an unauthenticated user, as a normal user, and as an administrative user, to test the application’s authentication and access control functions. LMNTRIX will use a combination of internally developed tools and scripts in addition to open source and commercial tools