TLP WHITE - FINAL
The entity should understand any scoping requirements of the authorities in relevant jurisdictions
and is encouraged to analyze their respective requirements. This is particularly important if the
entity wishes to use the results to satisfy any TLPT requirements of authorities from these
jurisdictions. In such cases, the entity should incorporate and liaise at the initial scoping phase
with all relevant authorities, who may provide guidance to the entity on the test scope.
During the lifecycle of a test, the scope and duration may evolve as a result of interactions
between threat intelligence and penetration testing providers, based on the results of their work.
There should be agreement by the relevant stakeholders (the entity, threat intelligence and
penetration testing providers, authorities, etc.) on the modifications to the scope with regard to
the authority’s requirements.
Risk Management
Entities, in consultations with their relevant stakeholders, should apply effective risk
management controls to reduce the risk of any potential impact to entity data, damage to entity
assets and disruption to critical services and/or operations at the entity or in the financial sector.
As part of risk management, the White Team may halt the test at any point, if it considers that
continued testing poses an unacceptable risk to the entity.
While communication within the entity should be kept to a minimum to protect the integrity of
the test, the entity should ensure appropriate risk management controls are communicated and
understood by all relevant stakeholders.
Findings Classification
During the Scoping Phase, stakeholders, including the penetration testing providers, should reach
agreement on the classification schema for vulnerabilities discovered during testing, as well as
on objectives that demonstrate successful compromise of the entity. The classification schema
aims to show criticality and priority of discovered vulnerabilities in line with the entity’s risk
management framework.
The scoping deliverable should be provided to the threat intelligence provider to help develop
intelligence-based scenarios for testing critical services.
Element 2: Resourcing
The entity is responsible for procuring threat intelligence and penetration testing providers. Due
to the sensitive nature of TLPT, entities should carefully select the threat intelligence and
penetration testing providers, based on factors such as level of expertise, ethical code of conduct
and adequate levels of assurance (e.g., indemnity insurance). Accreditation and certification can
be a method of validating the expertise of such providers.
While external threat intelligence and penetration testing providers generally offer an
independent perspective, their use may be subject to jurisdictional requirements. Entities should
confirm their approach meets the requirements of target jurisdictions at the scoping phase of the
process. For example, some jurisdictions may mandate the use of external threat intelligence and
penetration testing providers and validation of expertise by accreditation and certification
providers.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
4