Understanding Authorisation Print

  • 0

The requirement before anything.

WHY IT IS THE FIRST SUBJECT

Testing without authorisation is a criminal matter in most jurisdictions.

WHAT AUTHORISATION MUST COME FROM

Someone with authority over the systems concerned.

WHY AUTHORITY SPECIFICALLY

Permission from someone who does not own or control the system is not permission.

WHAT TO ESTABLISH

Who owns each system in scope Whether they have authorised the testing Whether anything is hosted or operated by a third party

WHY THIRD PARTIES MATTER

Systems you use but do not own require their provider's authorisation.

WHAT THAT INCLUDES

Hosting and cloud providers Software provided as a service Payment providers Anything operated on your behalf

WHAT TO ESTABLISH

Their policy on testing, and any notification required.

WHY

Testing a provider's infrastructure without permission breaches their terms and may be unlawful.

WHAT AUTHORISATION SHOULD BE

In writing Specific about what is in scope Specific about what is excluded Time-limited Signed by someone with authority

WHY TIME-LIMITED

Open-ended permission is not permission for anything at any time.

WHAT IT SHOULD SPECIFY

Systems and addresses in scope Techniques permitted and prohibited Testing window Emergency contacts on both sides What to do on discovering something critical

WHY EMERGENCY CONTACTS

Testing occasionally causes disruption and someone must be reachable.

WHAT TO ESTABLISH

That the authorisation exists before any activity begins.

WHAT TO NEVER DO

Test anything not explicitly in scope Continue outside the agreed window Rely on verbal permission


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot