The scope of the project
For this section, I reiterate the scope that we talked about with the stakeholders during our initial meetings. This includes things such as locations tested, IP space profiled, applications involved, and type of penetration testing (for example, external or internal). This way, anyone who reads the report understands what was tested as well as why it was tested and possibly what wasn't tested. For example, we may state that the scope of the penetration test was our Miami location and that the web applications for our online customer relations application were in scope for this test. We also need to mention any constraints that were put on the project, including items such as time frame, resources allocated, and budget ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access