Assessment without a provider.
WHAT YOU MAY DO
Test systems you own and control, subject to third-party terms.
WHAT TO ESTABLISH FIRST
That you have authority That providers permit it That you will not affect others
WHY OTHERS
Shared hosting and shared infrastructure mean your testing can affect other customers.
WHAT TO CHECK
Your provider's policy on testing.
WHAT MANY PROVIDERS REQUIRE
Notification in advance Restriction of certain techniques Prohibition of disruptive testing
WHAT TO NEVER DO
Test systems you do not own Test a provider's infrastructure rather than your own instance Use techniques that affect availability on shared infrastructure
WHAT INTERNAL CAPABILITY CAN USEFULLY DO
Regular scanning Configuration review against benchmarks Patch verification Review of exposed services Access review
WHY THOSE
They address the weaknesses most commonly exploited.
WHAT TO ESTABLISH
A baseline of what should be exposed.
WHAT TO MONITOR
Changes to it.
WHY
Services exposed unintentionally are a common cause of compromise.
WHAT TO REVIEW REGULARLY
Accounts and their access Systems no longer used Services running without reason
WHAT TO ESTABLISH ABOUT TOOLS
Where they come from, and that they are legitimate.
WHY
Security tools from unverified sources frequently contain something else.
WHAT TO ESTABLISH ABOUT SEPARATION
That testing is performed from a controlled environment.
WHAT TO RECORD
What was tested, when, and what was found.
WHAT TO RECOGNISE
The limits of internal testing.
WHY
Familiarity with your own systems obscures what an outsider would try.