SVC—12 · EXERCISE

Physical security exercise

A controlled physical exercise covers only named sites, with protected areas, a control team, and immediate stop authority.

Start scoping
Agreed physical rules of engagementPTES pre-engagement/reportingNIST SP 800-115 planning principles

TEST BOUNDARY

What sits inside the boundary

Sites, windows, objectives, authorized identities, and proof flags
Protected areas, prohibited actions, and coordination with law enforcement and guards
Evidence capture, privacy, and emergency contacts

ACCESS MODES

Knowledge level is scoped

Perimeter review
Controlled intrusion
Hybrid red-team scenario

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Objective timeline and control observations

Sanitized evidence with strict chain of custody

Facility and process improvements

EFFORT—DRIVER

Sites, shifts, and objectives

Travel, personnel, and safety coordination

Evidence restrictions and third parties

EXPLICIT—LIMIT

No forced entry, weapons, threats, theft, or dangerous impersonation

Protected areas and people are explicitly excluded

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft