What security testing should an SDET own (OWASP Top 10, auth, injection)?
Asked by The SDET Playbook
Asked Sep 28, 2026Viewed 0 times
What security testing should an SDET own (OWASP Top 10, auth, injection)?
Asked by The SDET Playbook
Sign in to answer and to vote.
Own the repeatable, automatable checks and route deep testing to security specialists. The OWASP Top 10:2025 is led by Broken Access Control, followed by Security Misconfiguration and Software Supply Chain Failures, with Injection at #5, and it adds Mishandling of Exceptional Conditions (improper error handling and failing open). For APIs, the OWASP API Security Top 10 (2023) puts Broken Object Level Authorization first. Good SDET-owned checks are automated authorization tests (user A cannot read or change user B's objects, and normal users cannot call admin functions), authentication and rate-limit tests, input validation and injection cases, security-header and misconfiguration checks, and dependency and secret scanning in CI. Only test systems you are authorized to test.
Sources: OWASP Top 10:2025 introduction, Reflectiz summary, OWASP API Security Top 10