- Penetration Testing Bootcamp
- Jason Beltrame
- 219字
- 2021-07-02 21:35:54
Defining objectives with stakeholder questionnaires
This section goes over the various questions that I have used, and That I think are important for this type of engagement. These will help define clear and measurable objectives for the penetration tester.
Let's have a look at a questionnaire to determine the engagement criteria:
- What is the objective of this penetration test?
- What will be the deliverables required at the end of the penetration test?
- What is the length of the penetration test, and is there any period of time when the penetration test cannot happen? (For example, the customer may have a busy period during the day when they don't want anything to interrupt their business processes)
- During the penetration test, does the penetration test stop at finding vulnerabilities, or does it proceed to actively try to exploit these vulnerabilities? (This question is important because the stakeholder may not want systems to be taken down or potential data modified/deleted, so we want to make sure we know the boundaries) If exploiting systems is acceptable, do you want the penetration tester to try lateral movement within the environment after that?
- Will this be an internal penetration test, an external penetration test, or both?
- Who are the contacts within the company?
- Are there any compliance standards that the company needs to follow?
推薦閱讀
- Vue.js快速入門與深入實(shí)戰(zhàn)
- Internet of Things with the Arduino Yún
- 鋒利的SQL(第2版)
- 深入RabbitMQ
- bbPress Complete
- 移動(dòng)界面(Web/App)Photoshop UI設(shè)計(jì)十全大補(bǔ)
- Android傳感器開發(fā)與智能設(shè)備案例實(shí)戰(zhàn)
- C編程技巧:117個(gè)問題解決方案示例
- SSH框架企業(yè)級(jí)應(yīng)用實(shí)戰(zhàn)
- 高效使用Greenplum:入門、進(jìn)階與數(shù)據(jù)中臺(tái)
- Koa與Node.js開發(fā)實(shí)戰(zhàn)
- Raspberry Pi開發(fā)實(shí)戰(zhàn)
- Access 2016數(shù)據(jù)庫應(yīng)用與開發(fā):實(shí)戰(zhàn)從入門到精通(視頻教學(xué)版)
- Mastering Python for Data Science
- 實(shí)戰(zhàn)圖解MACD波段交易技術(shù)