PTES
Pre-engagement: scope, authorisation and rules of engagement – PTES

PTES PTES-1.1: Define and record the scope in writing before testing

The organisation and the provider agree and document exactly what is to be tested before any testing begins. PTES treats scope as one of the most important and most overlooked parts of a test: the scope states the targets (specific addresses, ranges, domains or applications), whether intermediary systems such as firewalls, IDS or IPS and upstream or third-party providers are in or out of scope, the test type (for example a focused single-application test versus a broad find-a-way-in test), and any changes agreed during scoping. A signed statement of work records the work and the hours, and any work beyond it needs a further signed statement of work before it is done.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.34 Protection of information systems during audit testing

PCI DSS 4.0 · 1 control

  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Pre-engagement: scope, authorisation and rules of engagement – PTES

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.