Defined scope
In the kick-off meeting with the client, the scope of the project and the in-scope targets will have been defined. In this subsection of the report, all the defined in-scope URLs, IPs, endpoints, and so on should be mentioned. This information helps the technical team quickly manage the vulnerability at hand and communicate with the developer/administrator team that's responsible for the URLs/IPs mentioned in the scope.
There's another reason for adding the scope to the report – it makes for a smooth project flow for the penetration tester. In a scenario where the scope is undefined, the pentester won't be able to gauge the amount of work that needs to be done, or the number of days it will take to finish the project. As we ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access