ClearPenTest

Testing

Scope

Also called: testing scope, in scope, assessment boundary

Scope is the explicit list of systems, applications, networks, accounts and techniques included in a security assessment, and everything excluded from it. It determines what the resulting report can be used to claim.

Scope is where audit value is won or lost. A report whose scope does not cover the system in the SOC 2 system description or the ISO 27001 Statement of Applicability is evidence for something, but not for that audit.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.