TLP WHITE - FINAL The entity should understand any scoping requirements of the authorities in relevant jurisdictions and is encouraged to analyze their respective requirements. This is particularly important if the entity wishes to use the results to satisfy any TLPT requirements of authorities from these jurisdictions. In such cases, the entity should incorporate and liaise at the initial scoping phase with all relevant authorities, who may provide guidance to the entity on the test scope. During the lifecycle of a test, the scope and duration may evolve as a result of interactions between threat intelligence and penetration testing providers, based on the results of their work. There should be agreement by the relevant stakeholders (the entity, threat intelligence and penetration testing providers, authorities, etc.) on the modifications to the scope with regard to the authority’s requirements. Risk Management Entities, in consultations with their relevant stakeholders, should apply effective risk management controls to reduce the risk of any potential impact to entity data, damage to entity assets and disruption to critical services and/or operations at the entity or in the financial sector. As part of risk management, the White Team may halt the test at any point, if it considers that continued testing poses an unacceptable risk to the entity. While communication within the entity should be kept to a minimum to protect the integrity of the test, the entity should ensure appropriate risk management controls are communicated and understood by all relevant stakeholders. Findings Classification During the Scoping Phase, stakeholders, including the penetration testing providers, should reach agreement on the classification schema for vulnerabilities discovered during testing, as well as on objectives that demonstrate successful compromise of the entity. The classification schema aims to show criticality and priority of discovered vulnerabilities in line with the entity’s risk management framework. The scoping deliverable should be provided to the threat intelligence provider to help develop intelligence-based scenarios for testing critical services. Element 2: Resourcing The entity is responsible for procuring threat intelligence and penetration testing providers. Due to the sensitive nature of TLPT, entities should carefully select the threat intelligence and penetration testing providers, based on factors such as level of expertise, ethical code of conduct and adequate levels of assurance (e.g., indemnity insurance). Accreditation and certification can be a method of validating the expertise of such providers. While external threat intelligence and penetration testing providers generally offer an independent perspective, their use may be subject to jurisdictional requirements. Entities should confirm their approach meets the requirements of target jurisdictions at the scoping phase of the process. For example, some jurisdictions may mandate the use of external threat intelligence and penetration testing providers and validation of expertise by accreditation and certification providers. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 4

Select target paragraph3