PRACTICAL GUIDE · DRAFT FOR REVIEW
Scoping a penetration test
Use these questions to structure an initial conversation. The right approach depends on your organisation and the engagement.
Define the question
Explain what you want the test to establish, such as the resilience of an application or the exposure of an external environment.
Agree boundaries and authorisation
Identify the assets, owners, permitted activities and testing windows. Include relevant third-party dependencies in the scoping discussion.
Plan for operational impact
Agree contacts, escalation routes and stop conditions before testing begins.
Understand the output
Ask how severity, evidence and remediation advice will be presented to technical and business audiences.
Discuss follow-up
Clarify whether retesting is included and how fixes will be verified.