Boundary
In-scope and out-of-scope assets, environment, test window, source addresses, access, and third parties.
METHOD—STD
NIST and PTES provide the spine. OWASP, MASVS/MASTG, ATT&CK, and CVSS overlays are selected for the asset, tied to named versions and an explicit boundary.
Every test is recorded as structured data, not buried in an ambiguous paragraph.
Method and version, stable test ID, applicability, and the rationale for each exclusion.
Execution state, result, evidence, limitation, and accountable owner.
Blocked or unsuitable work remains visible in the final report.
Scanners and AI may help with discovery and drafting, but they do not approve findings.
Reproduces the finding, reasons about impact, and owns technical accuracy.
Challenges evidence, severity, context, remediation, and coverage.
Every finding and deliverable is approved by an accountable, qualified person.
The CVSS v4.0 score is published with its vector. Contextual priority remains separate and explains exposure, impact, evidence, and exploitability.
NEXT DECISION
The scoping interview connects assets, objectives, access, and constraints in a draft that receives human review.
Scope an engagement