Penetration Test - Planning and Scoping(6)

2021-01-18 11:14

阅读:698

标签:tween   task   resource   ann   test   restrict   oca   format   sources   

Penetration Test - Planning and Scoping(6)

  • Statement of Work(SOW)
    • Clearly states what tasks are to be accomplished
  • Master Service Agreement (MSA)
    • Specifies details of the business arrangement
  • Non-Disclosure Agreement (NDA)
    • An agreement that defines confidentiality, restrictions and/or sharing information

ENVIRONMENTAL DIFFERENCES

  • Export restrictions - restrictions on shipments, transfer of technology, or services outside the U.S.
    • See U.S. State Department resource - https://www.state.gov/strategictrade/overview
  • National or local restrictions
    • Differ among countries
    • Local customs differ
  • Corporate policies
    • Differ between most organizations

WRITTEN AUTHORIZATION

  • Obtain signature from the proper signing authority
    • "Get out of jail free" card
    • Pen tests can reveal sensitive or confidential information
    • Activities may be illegal without proper permission
    • Signed permission makes you a white hat pen tester
  • Third-party authorization when necessary
    • Ex: from a Cloud service provider
    • Get permission for any outside resources used
      • Cloud, Internet (ISP usage), etc.

QUICK REVIEW

  • Understand common contract types
  • Pay attention to localization restrictions
  • Always get written permission
  • Find out if you need third-party permission as well

Penetration Test - Planning and Scoping(6)

标签:tween   task   resource   ann   test   restrict   oca   format   sources   

原文地址:https://www.cnblogs.com/keepmoving1113/p/13347882.html


评论


亲,登录后才可以留言!