Quality assurance and testing organizations are tasked with the broad objective of assuring that a software application fulfills its functional business requirements. Such testing most often involves running a series of dynamic functional tests to ensure proper implementation of the application's features. However, because security is not a feature or even a set of features, security testing doesn't directly fit into this paradigm.
No takes yet. Share an insight, caveat, or question.
Arkin et al. (2005) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: