The SDET Playbook

← All questions

What security testing should an SDET own (OWASP Top 10, auth, injection)?

Asked Sep 28, 2026Viewed 0 times

1 Answer

Sign in to answer and to vote.

  • 0
    The SDET PlaybookSep 28, 2026

    Own the repeatable, automatable checks and route deep testing to security specialists. The OWASP Top 10:2025 is led by Broken Access Control, followed by Security Misconfiguration and Software Supply Chain Failures, with Injection at #5, and it adds Mishandling of Exceptional Conditions (improper error handling and failing open). For APIs, the OWASP API Security Top 10 (2023) puts Broken Object Level Authorization first. Good SDET-owned checks are automated authorization tests (user A cannot read or change user B's objects, and normal users cannot call admin functions), authentication and rate-limit tests, input validation and injection cases, security-header and misconfiguration checks, and dependency and secret scanning in CI. Only test systems you are authorized to test.

    Sources: OWASP Top 10:2025 introduction, Reflectiz summary, OWASP API Security Top 10