Defining what will be examined.
WHY SCOPE DETERMINES VALUE
Testing finds only what was in scope.
WHAT TO DEFINE
Systems, by address or identifier Applications and their components Whether supporting infrastructure is included User roles to be tested What is explicitly excluded
WHY EXPLICIT EXCLUSION
Ambiguity produces either untested systems or unauthorised testing.
WHAT TO ESTABLISH ABOUT APPROACH
How much information the tester receives.
WHAT THE OPTIONS BROADLY ARE
Testing with no prior information Testing with partial information Testing with full information and access
WHAT MORE INFORMATION PROVIDES
Deeper coverage in the available time.
WHAT LESS INFORMATION PROVIDES
An indication of what an outsider could discover.
WHY MORE INFORMATION USUALLY GIVES BETTER VALUE
Time spent discovering what you could simply tell them is time not spent testing.
WHAT TO ESTABLISH
Whether the objective is coverage or realism.
WHAT TO DEFINE ABOUT TECHNIQUES
Whether denial of service testing is permitted Whether social engineering is included Whether physical access is included Whether exploitation is permitted or only identification
WHY EXPLOITATION SPECIFICALLY
Proving a vulnerability may affect the system, and permission must be explicit.
WHAT TO ESTABLISH ABOUT PRODUCTION SYSTEMS
Whether testing occurs there or in a copy.
WHY IT MATTERS
Production testing risks disruption; testing a copy may not reflect reality.
WHAT TO ESTABLISH
Timing, to limit impact.
WHAT TO DEFINE ABOUT DATA
What the tester may access, and what they must not extract.
WHY
Systems contain personal and confidential data, and access carries obligations.