When testing is required of you.
WHO REQUIRES IT
Customers, particularly larger ones Regulators, in some sectors Payment and financial requirements Certification schemes Insurers, increasingly
WHAT THEY TYPICALLY REQUIRE
Testing at a defined frequency By a qualified provider Of a defined scope With evidence of remediation
WHY REMEDIATION EVIDENCE
A report of unresolved findings demonstrates nothing.
WHAT TO ESTABLISH
Exactly what the requirement is.
WHY EXACTLY
Requirements differ in scope, frequency and qualification of the tester.
WHAT TO ESTABLISH ABOUT THE PROVIDER
Whether the requirement specifies qualifications or accreditation.
WHAT TO PROVIDE WHEN ASKED
Confirmation that testing was performed Summary of findings and remediation Evidence of retest
WHAT NOT TO PROVIDE ROUTINELY
The full report.
WHY
It is a detailed description of your weaknesses.
WHAT TO ESTABLISH
What the requester actually needs.
WHAT USUALLY SUFFICES
A summary or attestation.
WHAT TO ESTABLISH IF THE FULL REPORT IS REQUIRED
How it will be protected and retained.
WHAT TO PREPARE
Documentation of your security practices generally.
WHY
Questions extend well beyond testing.
WHAT TO ESTABLISH
That your answers are accurate.
WHY
Overstating practices is verified and it ends relationships.
WHAT TO AVOID
Testing narrowly scoped to produce a clean report.
WHY
It satisfies the requirement and leaves you exposed, which is the outcome the requirement existed to prevent.