Methodology¶
Frameworks that give an engagement structure, so testing is repeatable, defensible, and mapped to recognized standards.
Why It Matters¶
A methodology keeps an engagement consistent from tester to tester, makes sure phases are not skipped under time pressure, and gives findings a shared vocabulary that clients and blue teams already understand. Many compliance requirements also expect testing to follow a recognized framework.
Frameworks¶
| Framework | Use |
|---|---|
| MITRE ATT&CK | Catalog of adversary tactics and techniques, used to plan coverage and map findings to real behavior |
| PTES | Penetration Testing Execution Standard: an end-to-end engagement model from pre-engagement to reporting |
| OWASP Testing Guide | Standard methodology for web application testing |
| NIST SP 800-115 | Technical guide to information security testing and assessment |
| SANS | SANS penetration testing framework and resources |
How I Use It¶
I pick the framework that fits the engagement: ATT&CK to plan and report technique coverage, the OWASP Testing Guide for web app work, and PTES as the overall spine from scoping through reporting. The framework keeps the work organized; the technique pages in the other sections are how each phase gets executed.