II.
Workflow overview
Reference · liveworkflow:penetration-testing
Penetration Testing Engagement overview
Plans and executes penetration testing engagements -- scoping target systems and attack surfaces, conducting reconnaissance and vulnerability exploitation, testing authentication and authorization boundaries, assessing data exfiltration risks, documenting findings with severity ratings, and coordinating remediation with engineering teams. Produces pen-test report and remediation priority list. Excludes ongoing vulnerability scanning.
Attributes
displayName
Penetration Testing Engagement
workflowKind
governance
triggerType
scheduled
typicalCadence
quarterly
complexity
cross-team
description
Plans and executes penetration testing engagements -- scoping target
systems and attack surfaces, conducting reconnaissance and
vulnerability exploitation, testing authentication and authorization
boundaries, assessing data exfiltration risks, documenting findings
with severity ratings, and coordinating remediation with engineering
teams. Produces pen-test report and remediation priority list.
Excludes ongoing vulnerability scanning.
Outgoing edges
applies_to_domain2
- domain:security·DomainSecurity
- domain:cybersecurity·DomainCybersecurity
involves_role3
- role:security-engineer·RoleSecurity Engineer
- role:chief-security-officer·RoleChief Security Officer
- role:backend-engineer·RoleBackend Engineer
requires_skill_area3
- skill-area:vulnerability-scanning·SkillAreaVulnerability Scanning
- skill-area:threat-modeling·SkillAreaThreat Modeling
- skill-area:application-security·SkillAreaApplication Security
triggers_responsibility2
- responsibility:security-audit·Responsibility
- responsibility:risk-assessment·ResponsibilityRisk Assessment
Incoming edges
None.