Prepare penetration tests sensibly
Determine the test objective, systems, access, test rules and results path before a penetration test.
- For whom
- IT managers, product teams, management and information security before an external security test.
- When to use it
- Before the offer and order and again immediately before the start of the active examination.
A penetration test is well prepared when the test objective, system boundaries, roles, permitted methods, test access, emergency contacts, report recipients and follow-up test are clearly agreed upon before the first active test.
Download PDFTarget and test area
A test needs a specific security question and clearly stated limits.
Safe test operation
Contacts, time windows and rules protect operations, evidence and test quality.
Result and resolution
Value only arises when discoveries are understood, prioritized and verifiably closed.
Result of the joint review
- A written test order
- A secure test and escalation path
- Usable reports for technology and management
- An agreed remediation and retesting process
Sources and professional basis
This working aid translates general recommendations into a compact initial review. The primary sources and your specific context remain decisive.
Frequently asked questions
Is an automatic vulnerability scan enough?
No. A scan can provide clues, but does not examine business logic, roles, attack chains and actual impact like a manual penetration test.
Should testing be carried out directly in production?
That depends on the goal and risk. Productive tests require particularly clear rules, accessible contacts, suitable data and a coordinated termination path.
Browser checkmarks are not stored or transmitted to sudo/PORT.