- Job title
- Penetration testing specialist
- Organization type
- a company within a holding
- Joined
- Nov 2023
- Message
- 154
Many people want testing, few are ready for it. In unprepared projects, half the findings are already known issues and the money is wasted.
One: provide the scope in writing. Which domains, which IP ranges, which applications. "Test everything" is not a valid scope.
Two: prepare the authorization document. If the system being tested isn't yours (cloud provider, hosting company), you need their permission too. This isn't a joke, it's a legal issue.
Three: test environment or production? If testing on production, specify the hours, who is on call, and who will roll back if something breaks — put it in writing.
Four: patch known vulnerabilities beforehand. Apply updates, change default passwords. Don't pay for these, they'll be found anyway.
Five: take backups and test if they restore properly. We don't want to test systems without backups.
Six: decide who will read the report. The report for the technical team and the summary for management are different documents.
Also, one more thing: never test without permission on any system that isn't yours. Try what you're curious about in an environment you set up yourself.