Choose objective-based testing goals
Start with what you need to know, such as whether an outside attacker could reach customer data, rather than a list of IP addresses. Objectives shape everything else.
Questions to ask
- What decision will the test results inform?
- Which assets or data would matter most if compromised?
- Is this a compliance test, a risk test or both?
