Vulnerability Assessment vs Penetration Test
● Vulnerability Assessment
o Credentialed
● Penetration Test
o Non-credentialed
Double-Blind Penetration Test
Double-Blind Test
▪ Much like the blind test, except the defenders are not informed about when the attack may occur
Scope of Work (SOW)
▪ Details the tasks to be performed which will include all the rules of
engagement that will be followed
Rules of Engagement (ROE)
▪ The ground rules both parties must abide by
● Timeline
● Location
● Time restrictions
● Transparency
● Boundaries
● Test Invasiveness
Software Composition Analysis
▪ The assessor inspects the source code to try to identify any open source component