SECURE GUIDE

Scope before
security testing.

An assessment should identify the systems, ownership, permitted techniques, testing window and important exclusions before active work starts.

TARGET

What is included?

List the domains, applications, networks or systems that the customer controls and wants assessed.

AUTHORITY

Who can approve testing?

Confirm the requester has authority to permit testing of every included target.

BOUNDARY

What is excluded?

Record prohibited techniques, third-party systems, timing constraints and operational sensitivities.

AUTHORISATION FIRST

Discuss the scope before testing.

Ask about a Security Review →