I would argue that since security is a requirement -- that if a quality test group exists, then that group would be somewhat responsible for testing for those security properties -- and that this would obviously be considered positive testing (not negative testing).