Planning

How to prepare for an authorized website security test

Published by MoShield · Updated

Make the scope concrete

Write down exact hostnames and applications. Identify third-party services and check whether separate approval is needed. A domain registration or invoice is useful context, but should not be treated as permission to test every connected service.

Plan around real operations

Tell the tester about fragile integrations, maintenance windows and actions that generate customer emails or financial events. Use approved test data where possible. Decide how both sides will communicate if an unexpected effect appears.

Prepare the handover

Name someone who can receive the report and someone who can implement changes. Agree the preferred report language and secure delivery method. MoShield's request workflow starts with contact and scope confirmation; submitting a form does not itself start testing.

Practical checklist

  • Confirm exact targets and exclusions.
  • Agree permitted actions and a stop condition.
  • Provide an operational contact.
  • Confirm report recipient and language.

A common question

Can testing start as soon as I submit the form?

No. Scope, authorization and the service arrangement must be confirmed first. Use the consultation process to resolve missing details.

Source and further reading

OWASP WSTG: reporting scope

General educational guidance, not a finding about your systems. Testing requires an agreed scope and authorization.