Put permission in writing
Name the systems you own or are authorized to test. Agree the scope, exclusions and rules of engagement before testing begins. Include third-party approvals where needed.
NIST — Technical Guide to Security Testing, SP 800-115Prepare the right access
List the applications, APIs and user roles in scope. Arrange dedicated test accounts and representative test data. Share access through an agreed secure channel, never a public chat.
OWASP — Web Security Testing GuideAgree when to pause
Confirm the test window, operational contacts and stop conditions. Decide how the team will escalate an urgent finding or unexpected disruption. Your service owners should know whom to contact.
NIST — Technical Guide to Security Testing, SP 800-115Make the report actionable
Ask for findings that explain affected assets, evidence, business impact and remediation. Keep sensitive evidence restricted to people who need it. A long vulnerability list is not a remediation plan.
OWASP — Web Security Testing GuidePlan beyond delivery
Assign owners to the fixes and arrange retesting. Keep testing within a wider security programme; a point-in-time assessment cannot guarantee that a system has no vulnerabilities.
OWASP — Web Security Testing GuidePreparation guidance only. The final test plan and permissions must be agreed with your authorized security and system owners.
