Agreeing Terms for Testing Print

  • 0

The contract.

WHAT TO AGREE IN WRITING

Scope, precisely Authorisation Techniques permitted and prohibited Timing and duration Deliverables Confidentiality Data handling and destruction Liability Insurance What happens on discovering a critical issue What happens on causing disruption

WHY DISRUPTION DESERVES A TERM

Testing can affect availability, and responsibility must be settled in advance.

WHAT TO ESTABLISH

Who bears the consequence of disruption caused within the agreed scope.

WHAT TO AGREE ABOUT CRITICAL FINDINGS

That they are reported immediately rather than held until the report.

WHY

A critical vulnerability left unreported for weeks is an unacceptable exposure.

WHAT TO ESTABLISH

An immediate notification route.

WHAT TO AGREE ABOUT EVIDENCE OF COMPROMISE

What happens if the tester finds signs that someone else has already been in.

WHY IT MATTERS

It changes the exercise from assessment to incident response.

WHAT TO ESTABLISH

That it is reported immediately and that testing stops.

WHAT TO AGREE ABOUT DATA

What may be accessed What may be copied What must be destroyed and when Evidence of destruction

WHY

Personal data accessed during testing carries obligations.

WHAT TO ESTABLISH ABOUT THE REPORT

Its format Whether a retest is included Who receives it How it is delivered securely

WHY SECURE DELIVERY

A penetration test report is a detailed description of how to compromise you.

WHAT TO ESTABLISH ABOUT RETENTION

That you control where it is stored.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot