A STRUCTURED APPROACH FOR PROCURING PENETRATION TESTING SERVICES

Stage A – Determine the business requirements for testing

  • Overview
  • Evaluate the drivers for conducting a penetration test
  • Identify target environment
  • Define the purpose of the penetration test
  • Produce requirements specification

Stage B – Agree testing scope

  • Overview
  • Determine testing style (eg. black, grey or white box testing)
  • Agree testing type (eg. web application or infrastructure testing)
  • Identify testing constraints
  • Produce scope statement

Stage C – Establish a management assurance framework

  • The need for a management assurance framework
  • Establish an assurance process
  • Define and agree contracts
  • Understand and mitigate risks
  • Introduce change management
  • Agree a problem resolution ...

Get Penetration Testing Services Procurement Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.