The requirement before anything.
WHY IT IS THE FIRST SUBJECT
Testing without authorisation is a criminal matter in most jurisdictions.
WHAT AUTHORISATION MUST COME FROM
Someone with authority over the systems concerned.
WHY AUTHORITY SPECIFICALLY
Permission from someone who does not own or control the system is not permission.
WHAT TO ESTABLISH
Who owns each system in scope Whether they have authorised the testing Whether anything is hosted or operated by a third party
WHY THIRD PARTIES MATTER
Systems you use but do not own require their provider's authorisation.
WHAT THAT INCLUDES
Hosting and cloud providers Software provided as a service Payment providers Anything operated on your behalf
WHAT TO ESTABLISH
Their policy on testing, and any notification required.
WHY
Testing a provider's infrastructure without permission breaches their terms and may be unlawful.
WHAT AUTHORISATION SHOULD BE
In writing Specific about what is in scope Specific about what is excluded Time-limited Signed by someone with authority
WHY TIME-LIMITED
Open-ended permission is not permission for anything at any time.
WHAT IT SHOULD SPECIFY
Systems and addresses in scope Techniques permitted and prohibited Testing window Emergency contacts on both sides What to do on discovering something critical
WHY EMERGENCY CONTACTS
Testing occasionally causes disruption and someone must be reachable.
WHAT TO ESTABLISH
That the authorisation exists before any activity begins.
WHAT TO NEVER DO
Test anything not explicitly in scope Continue outside the agreed window Rely on verbal permission