Scoping an Assessment Print

  • 0

Defining what will be examined.

WHY SCOPE DETERMINES VALUE

Testing finds only what was in scope.

WHAT TO DEFINE

Systems, by address or identifier Applications and their components Whether supporting infrastructure is included User roles to be tested What is explicitly excluded

WHY EXPLICIT EXCLUSION

Ambiguity produces either untested systems or unauthorised testing.

WHAT TO ESTABLISH ABOUT APPROACH

How much information the tester receives.

WHAT THE OPTIONS BROADLY ARE

Testing with no prior information Testing with partial information Testing with full information and access

WHAT MORE INFORMATION PROVIDES

Deeper coverage in the available time.

WHAT LESS INFORMATION PROVIDES

An indication of what an outsider could discover.

WHY MORE INFORMATION USUALLY GIVES BETTER VALUE

Time spent discovering what you could simply tell them is time not spent testing.

WHAT TO ESTABLISH

Whether the objective is coverage or realism.

WHAT TO DEFINE ABOUT TECHNIQUES

Whether denial of service testing is permitted Whether social engineering is included Whether physical access is included Whether exploitation is permitted or only identification

WHY EXPLOITATION SPECIFICALLY

Proving a vulnerability may affect the system, and permission must be explicit.

WHAT TO ESTABLISH ABOUT PRODUCTION SYSTEMS

Whether testing occurs there or in a copy.

WHY IT MATTERS

Production testing risks disruption; testing a copy may not reflect reality.

WHAT TO ESTABLISH

Timing, to limit impact.

WHAT TO DEFINE ABOUT DATA

What the tester may access, and what they must not extract.

WHY

Systems contain personal and confidential data, and access carries obligations.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot