Os Papéis · Quem defende
Penetration tester
Escrito a partir de fontes publicadas
The specialist who tests defences by behaving like an attacker, inside an agreement that says exactly what is permitted. The national skills framework places it at the second or third tier, normally reached after several years in security operations, which is worth stating because the role is frequently imagined as an entry point and is in practice an advanced one.
De quem recebe
- The client
- Scope, rules of engagement, and the authorisation that makes the work lawful.
- Threat intelligence and research
- Techniques currently in use, which is what makes the simulation realistic.
- Previous reports
- What was found last time, and what happened to it.
A quem serve
- The defenders
- Evidence of what an adversary could reach, obtained safely.
- Leadership
- A view of exposure grounded in demonstration rather than in inventory.
- The vulnerability management function
- The starting list, which they then carry over time.
Do que o trabalho depende
The technical work is shared with the adversary; the authorisation is what makes it a profession. Scope, rules of engagement and the discipline to stay inside them are the whole distinction, and they are also what makes the findings usable — a test conducted where somebody agreed it would be produces a report the organisation can act on, while anything obtained outside that boundary creates a problem rather than a finding. The good ones treat the scope document as the first deliverable rather than as paperwork preceding the real work.