# OSSTMM

[The Open Source Security Testing Methodology Manual](https://www.isecom.org/OSSTMM.3.pdf) provides a detailed framework of testing strategies for systems, software, applications, communications and the human aspect of cybersecurity.

The methodology focuses primarily on how these systems, applications communicate, so it includes a methodology for:

1. **Telecommunications (phones, VoIP, etc.)**
2. Wired Networks
3. Wireless communications

<table class="table table-bordered" id="bkmrk-advantages-disadvant"><tbody><tr><td style="background: #efefef;">**Advantages**</td><td style="background: #efefef;">**Disadvantages**</td></tr><tr><td>Covers various testing strategies in-depth.  
</td><td>The framework is difficult to understand, very detailed, and tends to use unique definitions.  
</td></tr><tr><td>Includes testing strategies for specific targets (I.e. telecommunications and networking)   
</td><td>*Intentionally left blank.*</td></tr><tr><td>The framework is flexible depending upon the organisation's needs.  
</td><td>*Intentionally left blank.*</td></tr><tr><td>The framework is meant to set a standard for systems and applications, meaning that a universal methodology can be used in a penetration testing scenario.  
</td><td>*Intentionally left blank.*</td></tr></tbody></table>