Application Security
Web, mobile, desktop
Testing the application itself against the OWASP Application Security Verification Standard (ASVS) and the OWASP Web Security Testing Guide: authentication, authorization, session handling, business logic, and the boundaries where user input reaches something that acts on it.