The invention relates to the technical field of the 
information security, in particular to a security evaluating and detecting method used for a cloud infrastructure. The method is completed by a device formed by a dispatching module, a 
testing software library, a testing mirror, a testing configuration 
library, a testing result 
library, an analysis module, a testing requirement docment, a testing report and other modules. Configuration operating is carried out on the 
testing software library by a user in advance before testing; 
security testing software which exists in the market and aims at the cloud infrastructure and independently programmed 
testing software programs are uploaded to the testing 
software library; classification is carried out on the 
software according to the usual classification, namely the 
system security, the 
network security, the 
data security, the behavior security and the like, and the software is partitioned to different 'testing software lists'; the testing software library can be continuously updated, and the advancement and the maturity of the testing software are guaranteed. The problem of compatibility of the 
information security testing method and the cloud calculation is solved, and the method can be used for security evaluating and testing of the cloud infrastructure.