Preparation

Summary

This component consists of trip preparation activities that are needed to ensure the technical and facilitated components of the audit are able to be conducted effectively and within the on-site time-frame and in coordination with the organization.

Purpose

A SAFETAG audit has a short time frame. Preparation is vital to ensure that time on the ground is not spent negotiating over the audit scope, updating the auditors systems, searching for missing hardware, or refreshing oneself with the SAFETAG framework. To that end negotiations with the host organization help reveal if the organization has the capacity to undertake the audit and respond to its findings.

Guiding Questions

The Flow of Information

Preparation Information Flow

Approaches

Outputs

Operational Security

Resources

Facilitation Preparation

Password Dictionary Creation

Other Pre-Engagement Resources

Incident Handling Resources

Data Security Standards

Activities

undefined


  1. " Some activities common in penetration tests may violate local laws. For this reason, it is advised to check the legality of common pentest tasks in the location where the work is to be performed."

  2. " Some activities common in penetration tests may violate local laws. For this reason, it is advised to check the legality of common pentest tasks in the location where the work is to be performed."

  3. "In addition, some service providers require advance notice and/or separate permission prior to testing their systems. For example, Amazon has an online request form that must be completed, and the request must be approved before scanning any hosts on their cloud. If this is required, it should be part of the document."

  4. NIST SP 800-115, Technical Guide to Information Security Testing and Assessment. Section 7.1 Coordination

  5. "Obviously, being able to get in touch with the customer or target organization in an emergency is vital."

  6. See the auditor trainee resource list

  7. APPENDIX A - Auditor travel kit checklist

  8. "Traveling teams should maintain a flyaway kit that includes systems, images, additional tools, cables, projectors, and other equipment that a team may need when performing testing at other locations."

  9. Auditor Tool Resource List - Password Dictionary Creation

  10. APPENDIX A - Auditor travel kit checklist

  11. "Traveling teams should maintain a flyaway kit that includes systems, images, additional tools, cables, projectors, and other equipment that a team may need when performing testing at other locations."

Activities

 

Developed with ❤ by

Information Innovation Lab

Applied research and development of public interest technology.