Authorize and scope
Confirm ownership, written authorization, systems in scope, permitted activity, timing, contacts, and exclusions.
Review websites, servers, access, configuration, backups, dependencies, and monitoring with a clearly defined scope and written authorization.
A useful review considers how the system is built, hosted, accessed, updated, backed up, monitored, and maintained. Findings are explained in business and technical terms so remediation can be prioritized.
Security capabilities
Choose a focused service or build a coordinated scope based on the system and risk.
Review application exposure, updates, access, hosting controls, and recovery readiness.
Review this serviceIdentify and prioritize weaknesses within an agreed and authorized scope.
Review this serviceExamine important system, application, and service configuration against the defined need.
Review this serviceReduce avoidable exposure through access, service, update, and configuration improvements.
Review this serviceContain, clean, restore, validate, and document post-incident improvements.
Review this serviceReview backup coverage, retention, access, and practical restoration readiness.
Review this serviceReview accounts, roles, credentials, and least privilege practices.
Review this serviceMonitor agreed availability and security-relevant signals.
Review this serviceTurn findings into prioritized, understandable technical work.
Review this serviceReview process
Confirm ownership, written authorization, systems in scope, permitted activity, timing, contacts, and exclusions.
Understand architecture, access, data sensitivity, current controls, known incidents, and operational constraints.
Perform only the activities approved in the documented scope.
Document evidence, severity, affected areas, business context, and prioritized remediation guidance.
Clarify findings, assist with agreed improvements, and verify changes when included in scope.
This checklist is a conversation starter, not a security score or a substitute for an authorized assessment.
Share the system owner, business context, systems in scope, known concerns, and desired outcome. No testing begins without written authorization.