Skip to content

Rules of Engagement & Ethical Hacking

By the end of this lesson, you will be able to:

  • Understand the importance of Rules of Engagement (RoE).
  • Learn the legal and ethical responsibilities of Cloud Penetration Testers.
  • Identify authorised and prohibited testing activities.
  • Understand scope management and risk reduction.
  • Apply professional standards during cloud penetration testing engagements.

A penetration test is not an attack.

It is an authorised security assessment conducted with permission to help an organisation improve its security posture.

Without clearly defined Rules of Engagement:

  • Systems may be disrupted.
  • Business operations may be affected.
  • Sensitive data may be exposed.
  • Legal issues may arise.
  • Trust between the client and security team may be damaged.

Every professional penetration testing engagement begins with agreed Rules of Engagement.


Rules of Engagement (RoE) define:

  • What can be tested.
  • What cannot be tested.
  • Who authorises the assessment.
  • When testing may occur.
  • Which techniques are permitted.
  • Communication procedures.
  • Escalation processes.
  • Emergency contacts.

They protect both the client and the penetration testing team.


A typical Rules of Engagement document includes:

Project Information
Scope
Objectives
Authorisation
Testing Schedule
Permitted Activities
Restricted Activities
Communication Plan
Emergency Contacts
Evidence Handling
Reporting Requirements

Always obtain written authorisation before beginning any penetration test.

Authorisation should include:

  • Organisation name
  • Project sponsor
  • Assessment objectives
  • Approved testers
  • Start and end dates
  • Systems in scope
  • Legal approval
  • Signatures

Never begin testing without explicit permission.


Scope determines which resources may be assessed.

Examples of in-scope assets:

  • AWS Accounts
  • Azure Subscriptions
  • Google Cloud Projects
  • Amazon EKS Clusters
  • Azure Kubernetes Service (AKS)
  • Google Kubernetes Engine (GKE)
  • Virtual Machines
  • APIs
  • Cloud Storage
  • Web Applications

Examples include:

  • Third-party services
  • Customer-managed infrastructure
  • Personal accounts
  • External suppliers
  • Production environments not explicitly approved
  • Shared cloud services outside the agreement

Always respect scope boundaries.


The tester has little or no prior knowledge of the environment.


The tester receives limited information such as user accounts or architecture details.


The tester receives extensive information including architecture diagrams, source code and cloud configurations.


Cloud assessments may include:

  • Cloud infrastructure review
  • IAM assessment
  • Kubernetes assessment
  • Storage security review
  • Network security assessment
  • Serverless security review
  • Container security review
  • Configuration assessment

Testing techniques should align with the agreed objectives.


A professional Cloud Penetration Tester should:

  • Protect customer data.
  • Respect privacy.
  • Follow approved scope.
  • Minimise operational impact.
  • Report findings honestly.
  • Maintain confidentiality.
  • Act with integrity.

Ethical behaviour builds trust and credibility.


Cloud penetration testing must comply with:

  • Applicable laws and regulations.
  • Customer contracts.
  • Cloud provider acceptable use policies.
  • Organisational security policies.
  • Data protection requirements.

When in doubt, stop and seek clarification before proceeding.


Major cloud providers generally allow authorised penetration testing against customer-owned resources, subject to their policies.

Before testing:

  • Confirm you own or are authorised to test the resources.
  • Review the provider’s current penetration testing guidance.
  • Ensure testing does not affect shared infrastructure or other customers.

Always follow the cloud provider’s published requirements.


Professional testing should aim to:

  • Identify vulnerabilities safely.
  • Validate security controls.
  • Avoid unnecessary disruption.
  • Protect business operations.
  • Preserve evidence.
  • Reduce organisational risk.

Security assessments should improve security—not create additional problems.


Depending on the approved scope, activities may include:

  • Asset discovery
  • IAM reviews
  • Configuration assessment
  • Kubernetes security assessment
  • Cloud storage review
  • Network validation
  • Security control verification
  • Vulnerability validation
  • Evidence collection
  • Security reporting

Only perform activities explicitly approved by the client.


Unless specifically authorised, avoid:

  • Denial-of-Service (DoS) testing
  • Destructive testing
  • Data deletion
  • Ransomware simulation
  • Production malware deployment
  • Credential theft
  • Business disruption
  • Testing third-party environments
  • Social engineering (unless separately approved)
  • Physical security testing

Restricted activities require additional approval and planning.


During long engagements:

  • Inform stakeholders before major testing phases.
  • Coordinate with operations teams.
  • Avoid maintenance windows unless agreed.
  • Document unexpected issues.
  • Pause testing if instructed.

Communication reduces operational risk.


A communication plan should identify:

Role Responsibility
Project Sponsor Overall approval
Security Team Assessment execution
Cloud Engineering Technical support
SOC Team Monitoring and alert handling
Incident Manager Emergency response
Business Owner Business coordination

Testing should stop immediately if:

  • Production stability is affected.
  • Sensitive data is unexpectedly exposed.
  • Critical business services fail.
  • Testing exceeds the approved scope.
  • A real security incident is discovered.
  • The customer requests testing to stop.

Document the reason and notify stakeholders immediately.


If you encounter sensitive information:

  • Do not copy more data than necessary.
  • Do not modify customer information.
  • Secure all evidence.
  • Limit access to authorised personnel.
  • Follow organisational data-handling procedures.
  • Include only necessary evidence in reports.

Collect evidence responsibly.

Examples include:

  • Configuration screenshots
  • IAM policies
  • Security Group settings
  • Kubernetes manifests
  • Logs
  • Cloud console screenshots
  • Command outputs
  • Configuration files

Protect all collected evidence from unauthorised access.


A professional finding should include:

  • Description
  • Technical details
  • Business impact
  • Evidence
  • Risk rating
  • Remediation recommendation

Avoid exaggerating risk or making unsupported claims.


Reports should be:

  • Accurate
  • Objective
  • Clear
  • Evidence-based
  • Reproducible
  • Actionable

Avoid unnecessary technical jargon when writing executive summaries.


Professional Cloud Penetration Testers should:

  • Respect customer systems.
  • Protect confidential information.
  • Communicate clearly.
  • Meet agreed deadlines.
  • Document all activities.
  • Follow industry best practices.
  • Continuously improve technical skills.

Your reputation is built on professionalism as much as technical expertise.


Customer Request
Written Authorisation
Scope Definition
Rules of Engagement
Assessment Planning
Testing
Evidence Collection
Reporting
Remediation
Retesting
Project Closure

Before beginning an engagement, verify:

  • Written authorisation received.
  • Scope documented.
  • Rules of Engagement approved.
  • Testing schedule confirmed.
  • Emergency contacts identified.
  • Communication plan established.
  • Cloud provider guidance reviewed.
  • Required access granted.
  • Evidence handling procedures defined.
  • Reporting format agreed.

Avoid:

  • Testing without written approval.
  • Exceeding the agreed scope.
  • Collecting unnecessary sensitive data.
  • Performing destructive tests without authorisation.
  • Ignoring customer communication.
  • Failing to document actions.
  • Assuming cloud provider permissions automatically allow all testing.

  • Obtain written approval before testing.
  • Follow the approved Rules of Engagement.
  • Keep stakeholders informed.
  • Minimise operational impact.
  • Protect customer information.
  • Document every significant action.
  • Report findings honestly and professionally.
  • Recommend practical remediations.
  • Respect legal and contractual obligations.

1. Why are Rules of Engagement essential for a penetration test?

Section titled “1. Why are Rules of Engagement essential for a penetration test?”

Answer: Rules of Engagement define the authorised scope, objectives, permitted activities and communication processes, helping ensure testing is conducted safely, legally and professionally.

2. Why should penetration testers always obtain written authorisation?

Section titled “2. Why should penetration testers always obtain written authorisation?”

Answer: Written authorisation provides formal permission to perform testing, establishes legal protection and confirms that the organisation has approved the assessment.

Answer: Scope management prevents accidental testing of unauthorised systems, reduces operational risk and ensures the engagement remains aligned with business objectives.

4. What should you do if you discover a real security incident during testing?

Section titled “4. What should you do if you discover a real security incident during testing?”

Answer: Follow the agreed incident-response and communication procedures, stop or pause testing if required, preserve evidence and notify the authorised customer contacts immediately.

5. Why is ethical conduct important for Cloud Penetration Testers?

Section titled “5. Why is ethical conduct important for Cloud Penetration Testers?”

Answer: Ethical conduct protects customer trust, safeguards sensitive information, ensures compliance with legal and contractual obligations and supports responsible security improvement.


  • Penetration testing is an authorised security assessment.
  • Rules of Engagement protect both the customer and the testing team.
  • Written authorisation is mandatory before testing.
  • Always respect the agreed scope and testing boundaries.
  • Professional communication and documentation are essential.
  • Protect customer data and minimise operational impact.
  • Follow legal, contractual and cloud provider requirements.
  • Ethical behaviour is a core responsibility of every Cloud Penetration Tester.

In the next lesson, we will learn how to Build Your Professional Cloud Penetration Testing Portfolio, including documenting labs, projects, assessment reports and evidence that demonstrate practical skills to employers and clients.

➡️ Next Lesson: Lesson 09 — Building Your Cloud Penetration Testing Portfolio