The organisation and the provider agree and document exactly what is to be tested before any testing begins. PTES treats scope as one of the most important and most overlooked parts of a test: the scope states the targets (specific addresses, ranges, domains or applications), whether intermediary systems such as firewalls, IDS or IPS and upstream or third-party providers are in or out of scope, the test type (for example a focused single-application test versus a broad find-a-way-in test), and any changes agreed during scoping. A signed statement of work records the work and the hours, and any work beyond it needs a further signed statement of work before it is done.
This control maps to 4 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.