00.3
Methodology
The same sequence every engagement, so you know what happens and when.
SCOPING
We agree what is in scope and what is not, how many roles exist, whether the API is included, and what a realistic time box looks like. The number moves with the answers, so this comes before any quote.
AUTHORISATION
Written authorisation from someone entitled to give it, naming the assets, the window, and the limits. Testing does not start without it. If the asset sits on infrastructure you do not own, the provider may need to authorise it too.
RULES OF ENGAGEMENT
Contact points on both sides, an escalation path for anything urgent, agreed handling of any data encountered, and what to do if something breaks. Denial of service and social engineering are out of scope unless explicitly agreed.
TESTING
Manual testing with tooling where tooling helps. Every candidate finding is investigated by hand to establish whether it is exploitable and how far it reaches. Anything critical is reported while testing is still running, not held back for the report.
REPORTING
An executive summary that a non technical owner can act on, and technical findings with CWE, a CVSS 3.1 vector, root cause, demonstrated impact, affected components and step by step remediation.
REMEDIATION
A debrief call to walk through the findings, and questions answered while your developers work through the fixes.
RETEST
One retest included. Fixed findings are re-verified and the report is reissued with their status updated.
ALIGNMENT
- OWASP WSTG
- The web application testing checklist that drives coverage.
- PTES
- Engagement structure, from pre engagement interaction through reporting.
- NIST SP 800-115
- Technical guide to information security testing and assessment.
- NÚKIB
- The Czech national cyber security authority publishes its own penetration testing methodology. Engagements are aligned to it where it applies.
