|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: [PEN-TEST] "Get out of Jail Free"
From: Gary Warner (glwarner
NARROWGATE.NET)Date: Tue Oct 31 2000 - 15:35:51 CST
- Next message: Alfred Huger: "[PEN-TEST] Dead Thread"
- Previous message: Briney, Andy: "[PEN-TEST] Article series on pen test, etc."
- In reply to: Shawn Davenport: "Re: [PEN-TEST] Your opinions are solicited ..."
- Next in thread: Gallicchio, Florindo (2007): "Re: [PEN-TEST] "Get out of Jail Free""
- Reply: Gary Warner: "[PEN-TEST] "Get out of Jail Free""
- Reply: Gallicchio, Florindo (2007): "Re: [PEN-TEST] "Get out of Jail Free""
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
We are being challenged by a client's legal department to get better "get out of
jail free" documentation.
I wondered what other professional penetration testers are doing for their
"liability" coverage. Language to the effect that we are going to access your
boxes, steal your passwords, root your boxes, view confidential information,
trick your employees, walk into secure areas without authorization, and if
anyone has a problem with that, we show our "Get out of Jail Free" card.
We have a little two-pager, but I've been advised by legal counsel for one of
our potential customers that its not worth the paper its written on.
Would love to hear opinions, or better yet see a sample doc that we could
template.
_-_
gar
- Next message: Alfred Huger: "[PEN-TEST] Dead Thread"
- Previous message: Briney, Andy: "[PEN-TEST] Article series on pen test, etc."
- In reply to: Shawn Davenport: "Re: [PEN-TEST] Your opinions are solicited ..."
- Next in thread: Gallicchio, Florindo (2007): "Re: [PEN-TEST] "Get out of Jail Free""
- Reply: Gary Warner: "[PEN-TEST] "Get out of Jail Free""
- Reply: Gallicchio, Florindo (2007): "Re: [PEN-TEST] "Get out of Jail Free""
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]