- Penetration Testing Bootcamp
- Jason Beltrame
- 219字
- 2021-07-02 21:35:54
Defining objectives with stakeholder questionnaires
This section goes over the various questions that I have used, and That I think are important for this type of engagement. These will help define clear and measurable objectives for the penetration tester.
Let's have a look at a questionnaire to determine the engagement criteria:
- What is the objective of this penetration test?
- What will be the deliverables required at the end of the penetration test?
- What is the length of the penetration test, and is there any period of time when the penetration test cannot happen? (For example, the customer may have a busy period during the day when they don't want anything to interrupt their business processes)
- During the penetration test, does the penetration test stop at finding vulnerabilities, or does it proceed to actively try to exploit these vulnerabilities? (This question is important because the stakeholder may not want systems to be taken down or potential data modified/deleted, so we want to make sure we know the boundaries) If exploiting systems is acceptable, do you want the penetration tester to try lateral movement within the environment after that?
- Will this be an internal penetration test, an external penetration test, or both?
- Who are the contacts within the company?
- Are there any compliance standards that the company needs to follow?
推薦閱讀
- INSTANT Mock Testing with PowerMock
- 精通軟件性能測試與LoadRunner實戰(zhàn)(第2版)
- Cassandra Data Modeling and Analysis
- PHP+MySQL+Dreamweaver動態(tài)網(wǎng)站開發(fā)實例教程
- Mastering Akka
- Python3.5從零開始學(xué)
- Julia for Data Science
- OpenCV with Python By Example
- Python 3 Object:oriented Programming(Second Edition)
- Learning Image Processing with OpenCV
- Python Penetration Testing Essentials
- Python機器學(xué)習(xí)
- Java程序設(shè)計(項目教學(xué)版)
- Learning GraphQL and Relay
- Python大數(shù)據(jù)與機器學(xué)習(xí)實戰(zhàn)