4 ms·
QA is focused on testing a product or system against how it should work. Security analysis tests against how it shouldn't. The second of those is a much larger
by _kb 3y ago
QA is focused on testing a product or system against how it should work. Security analysis tests against how it shouldn't. The second of those is a much larger search space. Both are important.
The argument around blame shifting is apt. The same case has been made for the usage of the term 'bug' (aka an externality). It's 2024, we don't have moths crawling into relays on our computers. We have implementation faults, invalid designs, unsound architecture, inaccurate documentation, ambiguous requirements, and a myriad of other ways to express how software may be defective.
Using those terms hurts, and may even invoke some level of concern from those outside of the engineering org - this is a great reason to embrace them.
- manquer 3y ago> QA is focused on testing a product or system against how it should work It would be pretty poor QA who only tested happy paths . Any competent quality analyst will be expected to test for failure states, boundary conditions and so on .