PTES
Pre-engagement: scope, authorisation and rules of engagement – PTES

PTES PTES-1.4: Agree the rules of engagement: how, when and where testing occurs

The rules of engagement, distinct from scope, set how the test is conducted: the timeline and any work breakdown, the locations and whether remote or on-site testing applies, the times of day permitted for testing, whether disruptive activities such as denial-of-service or stress testing are in or out of scope (and if in, that they run against a non-production environment mirroring production), whether the organisation's defenders will be informed (a blind or coordinated test, including whether traffic blocking or shunning is acceptable), and, where social engineering is in scope, the pretexts approved in writing. Scope creep is controlled through agreed start and end dates and a defined window for any retesting.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.34 Protection of information systems during audit testing

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Pre-engagement: scope, authorisation and rules of engagement – PTES

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.