Rules of engagement
Rules of engagement of security testing is a written document that defines what needs to be done during or after security assessment.
Rules of engagement define the following items/
Timeline of the assessment.
What is included in the assessment.
How to handle data, once the assessment is complete. The results of the security assessment often contain sensitive data, and it needs to be clearly defined what can be done with the results.
This document needs to also include expectations of behavior from the people of the organization against which the security assessment is done. If such a test is detected then should people allow it or block it?
Which resources are committed to this test.
Legal consequences of the test. Test needs to clearly define what is included in it.
How often results of the test needs to be reported?
Where the results of the test will be available.
Comments
Post a Comment