Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1153-1184 of 1801 terms

P
32

Penetration Testing Authorization

The formal permission and scope agreement that must be in place before any penetration test, defining what may be tested, when, and how, so testing is legal, bounded, and authorized rather than an actual attack.

Penetration testing authorization is the written agreement, often a rules-of-engagement and scope document plus explicit sign-off, that authorizes testing and defines its boundaries: targets, allowed techniques, timing, handling of findings, and emergency contacts. Without it, the same actions would be illegal. It protects both tester and client, prevents scope creep and collateral damage, and is the mandatory first step of any professional engagement. Testing outside authorization is never acceptable.

Introduced in: Web Application Penetration Testing

Examples

  • Signing a rules-of-engagement document before testing begins.
  • Defining authorized targets, techniques, and timing in scope.
  • Refusing to test systems outside the authorized scope.

No related terms linked yet.