We have listed some of the commonly asked questions and considerations that may be used as a basis to create a conventional customer requirements form. It is important to note that this list can be extended or shortened according to the goal of a client:
- Collect basic information, such as company name, address, website, contact person(s) details, email address, and telephone number(s)
- Determine the key objectives behind the penetration testing project
- Determine the penetration test type (with or without specific criteria):
- Black box testing
- White box testing
- External testing
- Internal testing
- Social engineering included
- Social engineering excluded
- Investigate employee background information
- Adopt an ...