Testing
Rules of engagement
Also called: ROE, testing authorization
Rules of engagement are the written agreement that defines what may be tested, when, by what methods, what is explicitly out of bounds, and who to contact if something goes wrong. They are what makes a penetration test lawful rather than an intrusion.
A usable set covers in-scope assets, excluded systems and techniques, the testing window, data handling rules for anything sensitive the tester encounters, escalation contacts on both sides, and confirmation that the person signing has authority to authorize testing of those systems.
The authority question is the one that gets skipped. Testing a system you do not own, on a cloud tenant you do not control, or through a provider whose terms prohibit it, is not authorized just because your customer asked for it.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.