Rules of engagement, written authorisation, scope, hours, test data, limits, emergency stop and contact chain.
Asset, identity, secret, dependency, Internet exposure and owner inventory.
Threat model: critical assets, trust boundaries, abuse scenarios, ATT&CK v19.1, controls and assumptions.
OWASP ASVS 5.0 and versioned WSTG to derive requirements and application verification cases.
CVSS v4.0 Base, Threat, Environmental and Supplemental, without reducing priority to the base score alone.
CISA KEV, observed exploitability, reachability, business impact, blast radius and SSVC to prioritise response.
RBAC/ABAC, separation of duties, PAM, JIT/JEA, phishing-resistant MFA and service account review.
Secret and key management: vault, rotation, scope, encryption at rest/in transit and usage log.
SAST, DAST, SCA, IaC/container scanning, SBOM, VEX, signing and provenance across the delivery chain.
Security telemetry: structured logs, timestamping, correlation, detection, ATT&CK coverage and retention.
Incident response aligned with CSF 2.0 / SP 800-61r3: preparation, detection, analysis, containment, eradication, recovery and lessons learned integrated into risk.
Remediation plan with owner, deadline, dependency, compensating control, accepted exception, evidence and re-audit.