Open source templates you can use to bootstrap your security programs

Announcing the External Penetration Testing Program Pack v1.1

Simplified_pentest_process

This release contains everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester. This will enable you to perform your first product or infrastructure level penetration test, and provide you with a process moving forward for future engagements.

In this pack, we cover:

Penetration testing preparation checklist: This checklist outlines everything you need to scope and perform a penetration test.

Penetration testing reporting requirements:  This document provides a list of minimal requirements that should be contained within a penetration testing report. Before finalizing a SOW with the vendor, look here first.

Penetration testing process workflow: Below is an outline of a simplified pentesting process with an external tester. It aligns roughly with the content in the penetration testing checklist.

 

GitHub: https://github.com/securitytemplates/sectemplates/tree/main/external-penetration-testing/v1

Updates: https://github.com/securitytemplates/sectemplates/blob/main/external-penetration-testing/v1/UPDATES.md

Original announcement: /2024/06/announce-the-external-penetration-testing-program-pack-10.html

Links

Announcements Only
Author main Twitter/X
Author main BlueSky

Categories

Leave a Reply

Your email address will not be published. Required fields are marked *