Rules of engagement
A set of clear rules of engagement should be established and approved by leadership and the legal department to ensure that tools, techniques, and procedures can be applied to simulate and emulate adversaries effectively. A superior penetration testing team holds itself accountable to the highest possible standard and works with excellence. This includes business ethics.
Therefore, it's important to establish rules that the team follows. Some examples are as follows:
- Do good! Always operate with due diligence.
- Do not perform denial-of-service testing or deny access to systems intentionally without explicit authorization.
- Consult the no-strike list before compromising assets. (A no-strike list is a set of assets or systems that are off-limits to the pen test team.)
- Operate surgically, rather than carpet bombing targets.
- Handle credentials and other sensitive security artifacts securely and safely during and after the conclusion of...