Rules of Engagement & Ethical Hacking
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
- Understand the importance of Rules of Engagement (RoE).
- Learn the legal and ethical responsibilities of Cloud Penetration Testers.
- Identify authorised and prohibited testing activities.
- Understand scope management and risk reduction.
- Apply professional standards during cloud penetration testing engagements.
Why Rules of Engagement Matter
Section titled “Why Rules of Engagement Matter”A penetration test is not an attack.
It is an authorised security assessment conducted with permission to help an organisation improve its security posture.
Without clearly defined Rules of Engagement:
- Systems may be disrupted.
- Business operations may be affected.
- Sensitive data may be exposed.
- Legal issues may arise.
- Trust between the client and security team may be damaged.
Every professional penetration testing engagement begins with agreed Rules of Engagement.
What are Rules of Engagement?
Section titled “What are Rules of Engagement?”Rules of Engagement (RoE) define:
- What can be tested.
- What cannot be tested.
- Who authorises the assessment.
- When testing may occur.
- Which techniques are permitted.
- Communication procedures.
- Escalation processes.
- Emergency contacts.
They protect both the client and the penetration testing team.
Enterprise Rules of Engagement
Section titled “Enterprise Rules of Engagement”A typical Rules of Engagement document includes:
Project Information
↓
Scope
↓
Objectives
↓
Authorisation
↓
Testing Schedule
↓
Permitted Activities
↓
Restricted Activities
↓
Communication Plan
↓
Emergency Contacts
↓
Evidence Handling
↓
Reporting RequirementsWritten Authorisation
Section titled “Written Authorisation”Always obtain written authorisation before beginning any penetration test.
Authorisation should include:
- Organisation name
- Project sponsor
- Assessment objectives
- Approved testers
- Start and end dates
- Systems in scope
- Legal approval
- Signatures
Never begin testing without explicit permission.
Defining Scope
Section titled “Defining Scope”Scope determines which resources may be assessed.
Examples of in-scope assets:
- AWS Accounts
- Azure Subscriptions
- Google Cloud Projects
- Amazon EKS Clusters
- Azure Kubernetes Service (AKS)
- Google Kubernetes Engine (GKE)
- Virtual Machines
- APIs
- Cloud Storage
- Web Applications
Out-of-Scope Systems
Section titled “Out-of-Scope Systems”Examples include:
- Third-party services
- Customer-managed infrastructure
- Personal accounts
- External suppliers
- Production environments not explicitly approved
- Shared cloud services outside the agreement
Always respect scope boundaries.
Types of Penetration Tests
Section titled “Types of Penetration Tests”Black Box
Section titled “Black Box”The tester has little or no prior knowledge of the environment.
Grey Box
Section titled “Grey Box”The tester receives limited information such as user accounts or architecture details.
White Box
Section titled “White Box”The tester receives extensive information including architecture diagrams, source code and cloud configurations.
Cloud Testing Approaches
Section titled “Cloud Testing Approaches”Cloud assessments may include:
- Cloud infrastructure review
- IAM assessment
- Kubernetes assessment
- Storage security review
- Network security assessment
- Serverless security review
- Container security review
- Configuration assessment
Testing techniques should align with the agreed objectives.
Ethical Responsibilities
Section titled “Ethical Responsibilities”A professional Cloud Penetration Tester should:
- Protect customer data.
- Respect privacy.
- Follow approved scope.
- Minimise operational impact.
- Report findings honestly.
- Maintain confidentiality.
- Act with integrity.
Ethical behaviour builds trust and credibility.
Legal Considerations
Section titled “Legal Considerations”Cloud penetration testing must comply with:
- Applicable laws and regulations.
- Customer contracts.
- Cloud provider acceptable use policies.
- Organisational security policies.
- Data protection requirements.
When in doubt, stop and seek clarification before proceeding.
Cloud Provider Policies
Section titled “Cloud Provider Policies”Major cloud providers generally allow authorised penetration testing against customer-owned resources, subject to their policies.
Before testing:
- Confirm you own or are authorised to test the resources.
- Review the provider’s current penetration testing guidance.
- Ensure testing does not affect shared infrastructure or other customers.
Always follow the cloud provider’s published requirements.
Safe Testing Principles
Section titled “Safe Testing Principles”Professional testing should aim to:
- Identify vulnerabilities safely.
- Validate security controls.
- Avoid unnecessary disruption.
- Protect business operations.
- Preserve evidence.
- Reduce organisational risk.
Security assessments should improve security—not create additional problems.
Activities Typically Permitted
Section titled “Activities Typically Permitted”Depending on the approved scope, activities may include:
- Asset discovery
- IAM reviews
- Configuration assessment
- Kubernetes security assessment
- Cloud storage review
- Network validation
- Security control verification
- Vulnerability validation
- Evidence collection
- Security reporting
Only perform activities explicitly approved by the client.
Activities Typically Restricted
Section titled “Activities Typically Restricted”Unless specifically authorised, avoid:
- Denial-of-Service (DoS) testing
- Destructive testing
- Data deletion
- Ransomware simulation
- Production malware deployment
- Credential theft
- Business disruption
- Testing third-party environments
- Social engineering (unless separately approved)
- Physical security testing
Restricted activities require additional approval and planning.
Change Control
Section titled “Change Control”During long engagements:
- Inform stakeholders before major testing phases.
- Coordinate with operations teams.
- Avoid maintenance windows unless agreed.
- Document unexpected issues.
- Pause testing if instructed.
Communication reduces operational risk.
Communication Plan
Section titled “Communication Plan”A communication plan should identify:
| Role | Responsibility |
|---|---|
| Project Sponsor | Overall approval |
| Security Team | Assessment execution |
| Cloud Engineering | Technical support |
| SOC Team | Monitoring and alert handling |
| Incident Manager | Emergency response |
| Business Owner | Business coordination |
Emergency Stop Procedure
Section titled “Emergency Stop Procedure”Testing should stop immediately if:
- Production stability is affected.
- Sensitive data is unexpectedly exposed.
- Critical business services fail.
- Testing exceeds the approved scope.
- A real security incident is discovered.
- The customer requests testing to stop.
Document the reason and notify stakeholders immediately.
Handling Sensitive Information
Section titled “Handling Sensitive Information”If you encounter sensitive information:
- Do not copy more data than necessary.
- Do not modify customer information.
- Secure all evidence.
- Limit access to authorised personnel.
- Follow organisational data-handling procedures.
- Include only necessary evidence in reports.
Evidence Collection
Section titled “Evidence Collection”Collect evidence responsibly.
Examples include:
- Configuration screenshots
- IAM policies
- Security Group settings
- Kubernetes manifests
- Logs
- Cloud console screenshots
- Command outputs
- Configuration files
Protect all collected evidence from unauthorised access.
Responsible Disclosure
Section titled “Responsible Disclosure”A professional finding should include:
- Description
- Technical details
- Business impact
- Evidence
- Risk rating
- Remediation recommendation
Avoid exaggerating risk or making unsupported claims.
Professional Reporting
Section titled “Professional Reporting”Reports should be:
- Accurate
- Objective
- Clear
- Evidence-based
- Reproducible
- Actionable
Avoid unnecessary technical jargon when writing executive summaries.
Professional Conduct
Section titled “Professional Conduct”Professional Cloud Penetration Testers should:
- Respect customer systems.
- Protect confidential information.
- Communicate clearly.
- Meet agreed deadlines.
- Document all activities.
- Follow industry best practices.
- Continuously improve technical skills.
Your reputation is built on professionalism as much as technical expertise.
Example Rules of Engagement Workflow
Section titled “Example Rules of Engagement Workflow”Customer Request
↓
Written Authorisation
↓
Scope Definition
↓
Rules of Engagement
↓
Assessment Planning
↓
Testing
↓
Evidence Collection
↓
Reporting
↓
Remediation
↓
Retesting
↓
Project ClosureEnterprise Engagement Checklist
Section titled “Enterprise Engagement Checklist”Before beginning an engagement, verify:
- Written authorisation received.
- Scope documented.
- Rules of Engagement approved.
- Testing schedule confirmed.
- Emergency contacts identified.
- Communication plan established.
- Cloud provider guidance reviewed.
- Required access granted.
- Evidence handling procedures defined.
- Reporting format agreed.
Common Mistakes
Section titled “Common Mistakes”Avoid:
- Testing without written approval.
- Exceeding the agreed scope.
- Collecting unnecessary sensitive data.
- Performing destructive tests without authorisation.
- Ignoring customer communication.
- Failing to document actions.
- Assuming cloud provider permissions automatically allow all testing.
Best Practices
Section titled “Best Practices”- Obtain written approval before testing.
- Follow the approved Rules of Engagement.
- Keep stakeholders informed.
- Minimise operational impact.
- Protect customer information.
- Document every significant action.
- Report findings honestly and professionally.
- Recommend practical remediations.
- Respect legal and contractual obligations.
Knowledge Check
Section titled “Knowledge Check”1. Why are Rules of Engagement essential for a penetration test?
Section titled “1. Why are Rules of Engagement essential for a penetration test?”Answer: Rules of Engagement define the authorised scope, objectives, permitted activities and communication processes, helping ensure testing is conducted safely, legally and professionally.
2. Why should penetration testers always obtain written authorisation?
Section titled “2. Why should penetration testers always obtain written authorisation?”Answer: Written authorisation provides formal permission to perform testing, establishes legal protection and confirms that the organisation has approved the assessment.
3. Why is scope management important?
Section titled “3. Why is scope management important?”Answer: Scope management prevents accidental testing of unauthorised systems, reduces operational risk and ensures the engagement remains aligned with business objectives.
4. What should you do if you discover a real security incident during testing?
Section titled “4. What should you do if you discover a real security incident during testing?”Answer: Follow the agreed incident-response and communication procedures, stop or pause testing if required, preserve evidence and notify the authorised customer contacts immediately.
5. Why is ethical conduct important for Cloud Penetration Testers?
Section titled “5. Why is ethical conduct important for Cloud Penetration Testers?”Answer: Ethical conduct protects customer trust, safeguards sensitive information, ensures compliance with legal and contractual obligations and supports responsible security improvement.
Key Takeaways
Section titled “Key Takeaways”- Penetration testing is an authorised security assessment.
- Rules of Engagement protect both the customer and the testing team.
- Written authorisation is mandatory before testing.
- Always respect the agreed scope and testing boundaries.
- Professional communication and documentation are essential.
- Protect customer data and minimise operational impact.
- Follow legal, contractual and cloud provider requirements.
- Ethical behaviour is a core responsibility of every Cloud Penetration Tester.
What’s Next?
Section titled “What’s Next?”In the next lesson, we will learn how to Build Your Professional Cloud Penetration Testing Portfolio, including documenting labs, projects, assessment reports and evidence that demonstrate practical skills to employers and clients.
➡️ Next Lesson: Lesson 09 — Building Your Cloud Penetration Testing Portfolio