Authorized Penetration Testing Rules
These operational rules help keep testing controlled, auditable and limited to the assets and activities approved by the client.
Stay In Scope
Do not test an asset merely because it is technically reachable. Test only explicitly authorized targets.
Minimize Impact
Prefer non-destructive validation and the minimum evidence needed to demonstrate a finding.
Protect Data
Do not unnecessarily access, copy, retain or disclose personal, financial or confidential information.
Stop on Risk
Immediately pause testing if there is unexpected service degradation, suspected data exposure or a client stop request.
Operational Rules
- Use client-approved test accounts whenever authentication is required.
- Do not attempt to access unrelated accounts or systems.
- Do not intentionally destroy, alter or encrypt production data.
- Do not conduct DoS/DDoS or stress testing unless separately and explicitly authorized with appropriate safeguards.
- Do not deploy malware, persistent backdoors or covert access mechanisms.
- Keep discovered vulnerabilities confidential and disclose them only to authorized recipients.
- Record material testing activity, timestamps and relevant evidence for the final report.
- Report critical findings promptly when the engagement rules require immediate notification.
Report Structure
A professional report should identify the scope, testing period, methodology, limitations, findings, evidence, risk context, remediation guidance and retest status. Where applicable, include timestamps, versions and evidence hashes. Avoid unnecessary customer data in screenshots or attachments.
