Try the following URL, csrc.nist.gov/publications/drafts/security-testing.pdf, it makes for some good reading.