
78 ◾ The Security Risk Assessment Handbook
© 2011 by Taylor & Francis Group, LLC
e permission form should specify the IP addresses and phone numbers (if
war dialing or social engineering) to be included in the test. e tests should be
restricted to a specied time window. If possible, the time window should not be
selected such that the organization can be ready and waiting for the test. A window
of at least seven days is typical. ere also may be a need for some extended hours
(over several days) to accommodate longer security scanning and test processes,
especially if the testing window is restricted to several o hours for each of those ...