A penetration test gives useful results only when it is well prepared. Most problems during testing come from an unclear scope, not from the testing itself.
Define the scope
Write down exactly what will be tested: which applications, addresses and environments. It is just as important to write down what will not be touched, for example third-party systems you have no permission to test.
Choose the type of test
- Black box: the tester has no prior information, like an outside attacker.
- Grey box: the tester has limited access, for example a user account.
- White box: the tester has the documentation and, where it makes sense, the source code.
The more information you provide, the deeper the test goes in the same amount of time.
Agree the rules
- Testing hours and periods when no testing should happen.
- Contacts on both sides and how a critical finding is reported.
- Whether tests that could affect availability are allowed.
- How any data the tester may see will be handled.
Prepare your team
Tell the team that monitors your systems, so they do not treat the test as a real attack. Take backups and make sure someone with technical knowledge is available during testing.
After the report
The report is the start of the work. Assign an owner and a deadline to each finding, fix the high-risk ones first, and ask for a retest to confirm the weaknesses are closed.
