Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow LOA Samples
EH-Net
May 23, 2013, 10:03:54 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: LOA Samples  (Read 8791 times)
0 Members and 1 Guest are viewing this topic.
Fenris
Guest
« on: August 01, 2006, 12:13:28 PM »

So Im drafting a few LOAs (letter of authorization) for employers for some Penetration Tests.  I havent ever drafted one from scratch before, and with just a few minutes of digging around I find several very rough outlines, generally with information like: make sure you include parameters, systems, etc. - good so far.

I was surprised that I could not find a few samples on line.  Maybe Im a poor google hacker, but I found samples for all sorts of stuff, except LOAs.

So, does anyone know of a site or reference point with some good sample letters in it - I am looking to bounce what I have against a standard of some sort, or at least take some formatting and inclusion tips.

Thanks to all.
Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #1 on: August 01, 2006, 12:44:10 PM »

Yeah I figured there would be more too, I found alot of sample policies but not many actual sample forms. Here's a few, hope they help

http://alertsite.com/AlertSite_Security_Scan_Authorization.pdf
http://www.auxs.umn.edu/files/SecurityScanPolicy.pdf
Logged
Fenris
Guest
« Reply #2 on: August 01, 2006, 12:58:44 PM »

Thanks, the second one is ballpark of my first draft.

I went back and added some additional stuff though, as it read like it was scanner permission as opposed to a full on pen test.

Thanks for the assist amigo.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #3 on: August 01, 2006, 01:30:43 PM »

Sounds like a good project for the members of EH...
Logged

CISSP
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #4 on: August 01, 2006, 03:21:22 PM »

I here you.

Fenris,

Would you be willing to contribute a sample form for publication?

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Fenris
Guest
« Reply #5 on: August 02, 2006, 10:56:58 AM »

Sure,

Hows about I draft a copy, removing all incriminating evidence, post it up here, and get some feedback.   Once we get some good feedback, we make a template out of it, and have it as a resource.

Im sure we could do other type forms as well as we go along.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #6 on: August 02, 2006, 11:06:18 AM »

Awesome. I love it.

Good suggestion Hug_It.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
tmartin
Recruiters
Newbie
*
Offline Offline

Posts: 46


View Profile
« Reply #7 on: August 02, 2006, 01:26:33 PM »

Yes, let's have it. I'm sure we'll have some good feedback for you...
Logged
Fenris
Guest
« Reply #8 on: August 04, 2006, 11:51:20 AM »

Heres a draft of whats currently in use by my employer all specific info dropped:

Attack & Penetration Authorization Form

The "Insert authority here" has authorized "Insert Tester Here" to operate and conduct A&P testing within Company's environment.  All A&P program activities must be approved in advance, in writing, by the "Insert Authority Position here" or Executive responsible for the system to be tested. 


Affected Business Unit(s) or Department(s)


Testing Dates


Targeted System(s) - (insert very specific information here, detailing the specific systems that you will target, and potentially what may NOT be targeted.


Objectives (insert what you are trying to test for here.  This is a reasonable general statement attached)

Authorized testing personnel will assess physical and logical network/system security and privacy controls in systems identified.  The assessment will entail both passive and active means of information gathering. 

Authorized personnel will attempt to gain access to sensitive private or proprietary information in an effort to evaluate the security measures currently enacted, and provide recommendations for improvement.


Authorized Exectuive
Name:
Title


Signature                                                                                  Date


Affected Business Unit / Department Authorization
Name:         
Title:         



Signature   / SOA               Date



Suggestions welcome.
Logged
Fenris
Guest
« Reply #9 on: August 22, 2006, 12:45:59 PM »

was it that good?

Fenris (been out of town for a couple weeks)
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #10 on: August 22, 2006, 03:38:46 PM »

Do we want to have a section that states whether it is a white, gray or black box test? How about something in regards to whether those in the affected business units / departments will be aware of the test?

How about a check box kind of form?

Type of Test

_ White Box
_ Gray Box
_ Black Box

What to Test

_ Entire Network
_ Wired Network
_ Wireless Network
_ Remote Access

Level of Penetration

_ Vulnerability Assessment
_ Penetrate DMZ Only
_ Penetrate Servers
_ Penetrate Workstations
_ Gather Files From Vulnerable Systems For Proof of Penetration

Etc, etc...

This way, it can be like a Sushi menu where the Executive can pick and choose what they want and/or specifically what the don't want.

Thoughts?

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.053 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.