I realize we're in the wild west still with the industry, but I disagree that pen-testers should be ready to spend time in jail. A far better solution, it seems to me, would be to make sure all police and security officers are trained to be aware that A) penetration tests exist and may occur and B) a process to authenticate a pen-tester when they're discovered.
We aren't in the wild west. I've been doing these engagements for more than 20 years. There are well worn guidelines for how to structure the contracts and other rules of engagement to prevent or mitigate this sort of overreaction.
I suspect (with zero evidence) that an over-eager sales rep or sales management booked a deal without contract due-diligence and a pen-test team trusted that the due-diligence had been done.
Comments
I realize we're in the wild west still with the industry, but I disagree that pen-testers should be ready to spend time in jail. A far better solution, it seems to me, would be to make sure all police and security officers are trained to be aware that A) penetration tests exist and may occur and B) a process to authenticate a pen-tester when they're discovered.
We aren't in the wild west. I've been doing these engagements for more than 20 years. There are well worn guidelines for how to structure the contracts and other rules of engagement to prevent or mitigate this sort of overreaction.
I suspect (with zero evidence) that an over-eager sales rep or sales management booked a deal without contract due-diligence and a pen-test team trusted that the due-diligence had been done.
Could you point me to them? Who sets them? Is there some kind of industry body?