METHOD—STD

A method that connects authority, coverage, evidence, and closure.

NIST and PTES provide the spine. OWASP, MASVS/MASTG, ATT&CK, and CVSS overlays are selected for the asset, tied to named versions and an explicit boundary.

01

Authorization and rules of engagement

Testing starts only after an agreed statement of work, rules of engagement, and signed written authorization are in place.

ROE—01

Boundary

In-scope and out-of-scope assets, environment, test window, source addresses, access, and third parties.

ROE—02

Safety

Prohibited actions, stop conditions, risk owner, and incident-reporting path.

ROE—03

Data handling

Evidence classification, storage region, encryption, access, retention, and deletion.

02

Coverage as structured data

Every test is recorded as structured data, not buried in an ambiguous paragraph.

MAP

Applicability

Method and version, stable test ID, applicability, and the rationale for each exclusion.

RUN

Execution

Execution state, result, evidence, limitation, and accountable owner.

LIMIT

Constraints

Blocked or unsuitable work remains visible in the final report.

03

Automation assists, humans remain accountable

Scanners and AI may help with discovery and drafting, but they do not approve findings.

LEAD

Engagement lead

Reproduces the finding, reasons about impact, and owns technical accuracy.

QA

Independent reviewer

Challenges evidence, severity, context, remediation, and coverage.

SIGN

Human sign-off

Every finding and deliverable is approved by an accountable, qualified person.

04

Technical severity is not business risk

The CVSS v4.0 score is published with its vector. Contextual priority remains separate and explains exposure, impact, evidence, and exploitability.

NEXT DECISION

Turn the method into a real working boundary.

The scoping interview connects assets, objectives, access, and constraints in a draft that receives human review.

Scope an engagement