Helps security firms and clients define a testing engagement so systems, methods, and rules of engagement are documented before any probing begins.
What's Included
- Systems in scope: IP ranges, applications, and assets cleared for testing.
- Testing methods: Penetration, vulnerability scan, or red-team approach and depth.
- Rules of engagement: Authorized windows, exclusions, and emergency contacts.
- Reporting and remediation: Findings format, severity ratings, and retest terms.
How To Use
- Clone the template and list the assets explicitly cleared for testing.
- Define the testing method, depth, and authorized time windows.
- Let an AI agent draft precise rules-of-engagement and exclusion clauses.
- Sign and lock the version before testing starts.
Track findings and remediation in one project with AI agents and clone more statement-of-work templates.
