Scope
- Domains and hostnames
- IP addresses when applicable
- paths and applications
- production or nonproduction environments
- authentication method
- allowed test classes
- rate and concurrency
- exclusions
- stop conditions
Prohibited without separate approval
- Denial-of-service testing
- credential attacks
- social engineering
- persistence
- malware
- destructive changes
- access to third-party systems
- collection of sensitive data beyond proof
Unexpected exposure
Stop the affected test, preserve the minimum evidence, avoid further access, and contact the designated customer and Asuruas security contacts.
Operational implementation
- Assign an owner for implementing and reviewing the obligations described in Authorized Testing Policy.
- Map the policy to product settings, contracts, support procedures, data flows, records, and staff responsibilities.
- Keep the public language aligned with actual production behaviour and contracted commitments.
- Retain approval, effective-date, change-history, and customer-notice records.
Review triggers
- A material product, pricing, data-processing, security, vendor, or support change.
- A new jurisdiction, customer class, contract requirement, or regulatory obligation.
- An incident, complaint, audit finding, or operational exception that shows the published process is incomplete.
- A change that could create testing outside the approved scope or at an unsafe rate.
Turn authorized testing policy into an accountable record.
An implementation checklist showing where Authorized Testing Policy is reflected in product behaviour and business procedure.