码迷,mamicode.com
首页 > Web开发 > 详细

Penetration Test - Planning and Scoping(6)

时间:2020-07-21 01:05:18      阅读:99      评论:0      收藏:0      [点我收藏+]

标签:tween   task   resource   ann   test   restrict   oca   format   sources   

Penetration Test - Planning and Scoping(6)

  • Statement of Work(SOW)
    • Clearly states what tasks are to be accomplished
  • Master Service Agreement (MSA)
    • Specifies details of the business arrangement
  • Non-Disclosure Agreement (NDA)
    • An agreement that defines confidentiality, restrictions and/or sharing information

ENVIRONMENTAL DIFFERENCES

  • Export restrictions - restrictions on shipments, transfer of technology, or services outside the U.S.
  • National or local restrictions
    • Differ among countries
    • Local customs differ
  • Corporate policies
    • Differ between most organizations

WRITTEN AUTHORIZATION

  • Obtain signature from the proper signing authority
    • "Get out of jail free" card
    • Pen tests can reveal sensitive or confidential information
    • Activities may be illegal without proper permission
    • Signed permission makes you a white hat pen tester
  • Third-party authorization when necessary
    • Ex: from a Cloud service provider
    • Get permission for any outside resources used
      • Cloud, Internet (ISP usage), etc.

QUICK REVIEW

  • Understand common contract types
  • Pay attention to localization restrictions
  • Always get written permission
  • Find out if you need third-party permission as well

Penetration Test - Planning and Scoping(6)

标签:tween   task   resource   ann   test   restrict   oca   format   sources   

原文地址:https://www.cnblogs.com/keepmoving1113/p/13347882.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!