Test objectives, success criteria, and threat scenarios must be agreed in advance so findings and the final report can be assessed against business risk rather than raw vulnerability counts.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
Other controls in PTES: Pre-Engagement Interactions