Planning for Your Next Pentest
Risk Management Register
Creating a Risk Management Register
Prioritization of Risks and Responses
Knowledge Database
Creating a Knowledge Database
Sanitization of Findings
Project Management
Knowledge Database
Points of contacts internal to the company
Points of contacts of client organizations
Resource vendors
List of subject-matter experts
List of past team members and current contact information
Contracts
Statements of work
Project templates
After-Action Review
Project Assessments
Scheduling issues (too little time, too much time, and so forth)
Resource availability
Risk management
Project scope issues (too broad, too narrow, and so forth)
Communication issues
Team Assessments
Technical strengths
Technical weaknesses
Level of effort within each component of the project
Team training ideas
Time management skills
Obstacles that prevented effective teamwork
Overall opinion on productivity of the team