{"id":55219,"date":"2025-09-02T03:06:43","date_gmt":"2025-09-02T03:06:43","guid":{"rendered":"https:\/\/www.process.st\/templates\/?p=55219"},"modified":"2026-02-16T17:07:04","modified_gmt":"2026-02-16T17:07:04","slug":"process-template-for-penetration-testing-under-dora-2","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/process-template-for-penetration-testing-under-dora-2\/","title":{"rendered":"Process Template for Penetration Testing Under DORA"},"content":{"rendered":"\n<section id=\"define-scope-of-penetration-testing\">\n <h2>Define scope of penetration testing<\/h2>\n <div class=\"image-content\">\n  <figure>\n   <a href=\"https:\/\/ps-attachments.s3.amazonaws.com\/3\/oUVYvn2BAaC7oM-CrSRNwA\/iZNplzAOxc6ZS74ydTJKCQ\/Process-Template-for-Penetration-Testing-Under-DORA.png\" alt=\"Define scope of penetration testing\" target=\"_blank\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/ps-attachments.s3.amazonaws.com\/3\/oUVYvn2BAaC7oM-CrSRNwA\/iZNplzAOxc6ZS74ydTJKCQ\/Process-Template-for-Penetration-Testing-Under-DORA.png\"> <\/a><!-- No caption -->\n  <\/figure>\n <\/div>\n <div class=\"text-content\">Defining the scope of penetration testing sets the foundation for the entire project. It helps to clarify what systems, applications, and data will be tested, ensuring that we focus our efforts where they are most needed. How do we know if we've covered everything necessary? By having a well-defined scope! This will also mitigate the risk of unauthorized testing and maintain organizational compliance. We need to gather input from stakeholders and outline critical business assets. Be prepared for questions about what happens if the scope isn't properly defined\u2014would that lead to potential vulnerabilities being overlooked? With the right resources, like a checklist of assets and stakeholders, we can navigate this process smoothly!<\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Penetration Testing Scope <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"multi-choice-content form-field-content\">\n  <div class=\"form-group\">\n   <label> List of stakeholders involved <\/label> <select disabled class=\"form-control\"> <option value=\"\">Multiple options can be selected from this list<\/option> <\/select>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">IT Security Team<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Management<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Legal Department<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Third-Party Vendors<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Compliance Officers<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"identify-target-systems-and-applications\">\n <h2>Identify target systems and applications<\/h2>\n <div class=\"text-content\">Now that we have our scope defined, it\u2019s time to identify the target systems and applications for our penetration test. This is essential, as it helps in focusing our testing efforts on critical assets. What specific systems do we want to test? Talk to your technical teams to ensure you don\u2019t miss anything! Remember, each system might present its own unique challenges and vulnerabilities, so gather as much data as you can. By identifying targets, we prepare ourselves to uncover potential weaknesses effectively. Proper documentation of applications, servers, and databases is crucial, so let\u2019s gather our resources!<\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Target identification tasks <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">List all web applications<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Identify database systems<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Identify network segments<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Gather operating system details<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Document third-party services<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"gather-relevant-documentation-and-assets\">\n <h2>Gather relevant documentation and assets<\/h2>\n <div class=\"text-content\">With our targets identified, it\u2019s now time to gather relevant documentation and assets. Why is this important? Well, having comprehensive documentation allows us to understand system functionality and architecture, potentially revealing where vulnerabilities may lie. What documents do we need? Think along the lines of network diagrams, system manuals, and previous security assessments. This task not only enhances our understanding but also can speed up the testing process by allowing us to anticipate where to look for issues. What challenges might arise? Lack of documentation can delay processes, so always have a plan to fill the gaps!<\/div>\n <div class=\"select-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Type of documentation needed <\/label> <select disabled class=\"form-control\"> <option value=\"An option will be selected here\">An option will be selected here<\/option> <\/select>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Network diagrams<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">System manuals<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Previous security assessments<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Compliance documentation<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Configuration files<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"conduct-reconnaissance-on-target\">\n <h2>Conduct reconnaissance on target<\/h2>\n <div class=\"text-content\">Time to don our detective hats! Conducting reconnaissance on our targets is about gathering information without touching the systems directly. It\u2019s an essential step in understanding potential attack vectors. What will we find during reconnaissance? We can identify open ports, services, and even misconfigured systems by using tools like Nmap or Recon-ng. The challenge here lies in the temptation to go too deep too early\u2014patience is key! This task sharpens our approach and arms us with the data we need for the next steps, so let\u2019s leverage our research skills!<\/div>\n <div class=\"members-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Assign reconnaissance team member <\/label> <select disabled class=\"form-control\"> <option value=\"A member or group will be selected here\">A member or group will be selected here<\/option> <\/select>\n  <\/div>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Tool used for reconnaissance <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"perform-vulnerability-assessment\">\n <h2>Perform vulnerability assessment<\/h2>\n <div class=\"text-content\">The big moment has arrived: performing our vulnerability assessment! This is where we actively scan and test our systems for known vulnerabilities. Are we using the right tools? Ensure you have information from the prior tasks to make informed scans with tools like Nessus or OpenVAS. But beware\u2014overlooking certain vulnerabilities can happen if we don\u2019t follow a systematic approach. Documenting our efforts thoroughly will pay off, as this forms the base for our exploitation phase. Ready to uncover weaknesses?<\/div>\n <div class=\"multi-choice-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Scanners used in assessment <\/label> <select disabled class=\"form-control\"> <option value=\"\">Multiple options can be selected from this list<\/option> <\/select>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Nessus<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">OpenVAS<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Qualys<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Burp Suite<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Acunetix<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"exploit-identified-vulnerabilities\">\n <h2>Exploit identified vulnerabilities<\/h2>\n <div class=\"text-content\">It\u2019s time to put our findings to the test by exploiting identified vulnerabilities. This task goes from theory to practice, allowing us to determine how deeply the vulnerabilities can be exploited. What\u2019s the goal? To understand the impact of these vulnerabilities in real-world scenarios. Is it safe? Following ethical guidelines is paramount here, ensuring we stay within our defined scope! Remember, this phase helps us to validate the vulnerabilities we\u2019ve been documenting. Gather your tools and let\u2019s see what we can uncover!<\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Exploitation tasks <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Gain access using exploits<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Attempt privilege escalation<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Test different services<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Perform web application attacks<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Document successful exploits<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"postexploitation-analysis\">\n <h2>Post-exploitation analysis<\/h2>\n <div class=\"text-content\">What happens after we exploit a vulnerability? Welcome to post-exploitation analysis! This crucial step allows us to understand the full implications of our findings. How deep did we get, and what sensitive data did we uncover? We should document everything for accountability and future reference. This isn\u2019t just about celebrating successes; it\u2019s about assessing the potential damage that could occur if these vulnerabilities were exploited by malicious actors. Let\u2019s ensure we are thorough, well-documented, and prepared for the next task!<\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Findings from post-exploitation analysis <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"number-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Potential data accessed during exploitation <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"document-findings-and-recommendations\">\n <h2>Document findings and recommendations<\/h2>\n <div class=\"text-content\">All our hard work leads to this\u2014documenting our findings and providing actionable recommendations! This is about transforming raw data into meaningful insights that could improve our security posture. What did we find, and how should we suggest fixes? Clarity and organization are key here to ensure stakeholders can grasp the implications easily. Plan for potential challenges in presenting your findings, such as technical jargon that may confuse non-technical stakeholders. Let\u2019s turn our findings into a constructive discussion!<\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Detailed findings <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"multi-choice-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Level of severity of findings <\/label> <select disabled class=\"form-control\"> <option value=\"\">Multiple options can be selected from this list<\/option> <\/select>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Critical<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">High<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Medium<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Low<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Informational<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"review-findings-against-scope\">\n <h2>Review findings against scope<\/h2>\n <div class=\"text-content\">It\u2019s always a good practice to review our documented findings against the initial scope of work. This task serves as a quality check, verifying we covered all agreed-upon areas. Are there any discrepancies? It\u2019s better to catch those now rather than later! This review also allows us to confirm the validity of our findings and make sure we didn\u2019t miss any vulnerabilities. By keeping a thorough checklist, we can enhance the credibility of our reports. After all, what is more important than delivering quality findings? Let\u2019s be diligent!<\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Scope review items <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">1<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Compare findings to original scope<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">2<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Verify vulnerability severity<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">3<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Check compliance requirements<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">4<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Ensure no missed targets<\/div>\n   <\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">5<\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">Document review outcomes<\/div>\n   <\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"approval-project-manager\">\n <h2>Approval: Project Manager<\/h2>\n <div class=\"approval-content\">\n  <div class=\"header\">\n   <div class=\"list-title\">Will be submitted for approval:<\/div>\n  <\/div>\n  <div class=\"approval-rule-subject-tasks-list\">\n   <ul class=\"list\">\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Define scope of penetration testing<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Identify target systems and applications<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Gather relevant documentation and assets<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Conduct reconnaissance on target<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Perform vulnerability assessment<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Exploit identified vulnerabilities<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Post-exploitation analysis<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Document findings and recommendations<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Review findings against scope<\/span>\n        <div class=\"body\">Will be submitted<\/div>\n       <\/div>\n      <\/div>\n     <\/div>\n    <\/li>\n   <\/ul>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"prepare-final-report\">\n <h2>Prepare final report<\/h2>\n <div class=\"text-content\">Now, let\u2019s wrap everything up with preparing the final report! This document will encapsulate our entire penetration testing process, findings, and recommendations. What format will best present our information? Consider the audience and the clarity of the report. Challenges may arise in ensuring all important data is conveyed succinctly without overwhelming the reader. Make use of visuals where possible\u2014the right charts and graphs can boost understanding! Remember, this report isn\u2019t just a formality; it\u2019s a key communication tool!<\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Summary of report sections <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"email-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Email for final report delivery <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"deliver-report-to-stakeholders\">\n <h2>Deliver report to stakeholders<\/h2>\n <div class=\"text-content\">With our final report in hand, it\u2019s now time to deliver it to the stakeholders! This task is about ensuring our findings reach the right people in a timely manner. How will we deliver it? Consider both digital and physical copies, as well as the need for briefings. Remember that discussing sensitive findings might require careful phrasing to avoid unnecessary panic. Following up post-delivery can also help clarify points and generate meaningful discussions. Let\u2019s make this delivery count!<\/div>\n <div class=\"send-rich-email-content form-field-content\">\n  <!-- No Recipients -->\n  <!-- No Recipients -->\n  <!-- No Recipients -->\n  <div class=\"form-group subject\">\n   <label>Subject<\/label>\n   <p class=\"form-control-static\">Penetration Testing Report Delivery<\/p>\n  <\/div>\n  <div class=\"form-group body\">\n   <label>Body<\/label> <iframe srcdoc=\"&lt;p&gt;Dear Stakeholders,&lt;\/p&gt;&lt;p&gt;Please find attached the final report of our recent penetration test. The report includes our findings, recommendations, and a summary of the testing scope.&lt;\/p&gt;&lt;p&gt;Feel free to reach out if you have any questions or require further discussion.&lt;\/p&gt;&lt;p&gt;Best,&lt;\/p&gt;&lt;p&gt;[Your Name]&lt;\/p&gt;\n&lt;style&gt;*{font-family:Inter,&quot;Segoe UI&quot;,&quot;Roboto&quot;,&quot;Oxygen&quot;,&quot;Ubuntu&quot;,&quot;Cantarell&quot;,&quot;Fira Sans&quot;,&quot;Droid Sans&quot;,&quot;Helvetica Neue&quot;,system-ui,sans-serif}&lt;\/style&gt;\n\" sandbox=\"\"><\/iframe>\n  <\/div>\n  <div class=\"form-group\">\n   <button type=\"button\" disabled class=\"btn btn-default\"><i class=\"fa fa-envelope btn-icon\"><\/i> Send<\/button>\n  <\/div>\n <\/div>\n <div class=\"members-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Select members to notify <\/label> <select disabled class=\"form-control\"> <option value=\"A member or group will be selected here\">A member or group will be selected here<\/option> <\/select>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"conduct-debrief-with-stakeholders\">\n <h2>Conduct debrief with stakeholders<\/h2>\n <div class=\"text-content\">Finally, it\u2019s time for a debrief with stakeholders to discuss our findings and their implications! This is where we can communicate directly with our audience, clarify concerns, and propose action plans based on our assessment. How can we ensure that the debrief is effective? Prepare to answer questions and facilitate conversations that lead to proactive solutions. Highlights from the report should guide our discussion. Always seek feedback to improve not just this process, but future engagements as well. Let\u2019s make this debrief an insightful experience!<\/div>\n <div class=\"email-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Email for debrief scheduling <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"number-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Phone number for follow-up <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Define scope of penetration testing Defining the scope of penetration testing sets the foundation for the entire project. It helps to clarify what systems, applications, and data will be tested, ensuring that we focus our efforts where they are most needed. How do we know if we've covered everything necessary? By having a well-defined scope! [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"\ud83d\udee1\ufe0f","cover_icon_url":"","tasks_count":"13","template_description":"Optimize your penetration testing workflow under DORA with this comprehensive process template, ensuring robust security assessments and actionable insights.","template_id":"twZEgwVz87fUu6Ha_thELw","task_0":"Define scope of penetration testing","task_slug_0":"define-scope-of-penetration-testing","task_1":"Identify target systems and applications","task_slug_1":"identify-target-systems-and-applications","task_2":"Gather relevant documentation and assets","task_slug_2":"gather-relevant-documentation-and-assets","task_3":"Conduct reconnaissance on target","task_slug_3":"conduct-reconnaissance-on-target","task_4":"Perform vulnerability assessment","task_slug_4":"perform-vulnerability-assessment","task_5":"Exploit identified vulnerabilities","task_slug_5":"exploit-identified-vulnerabilities","task_6":"Post-exploitation analysis","task_slug_6":"postexploitation-analysis","task_7":"Document findings and recommendations","task_slug_7":"document-findings-and-recommendations","task_8":"Review findings against scope","task_slug_8":"review-findings-against-scope","task_9":"Approval: Project Manager","task_slug_9":"approval-project-manager","task_10":"Prepare final report","task_slug_10":"prepare-final-report","task_11":"Deliver report to stakeholders","task_slug_11":"deliver-report-to-stakeholders","task_12":"Conduct debrief with stakeholders","task_slug_12":"conduct-debrief-with-stakeholders","task_13":"","task_slug_13":"","task_14":"","task_slug_14":"","task_15":"","task_slug_15":"","task_16":"","task_slug_16":"","task_17":"","task_slug_17":"","task_18":"","task_slug_18":"","task_19":"","task_slug_19":"","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[74,6,54],"tags":[],"class_list":["post-55219","post","type-post","status-publish","format-standard","hentry","category-compliance","category-finance","category-risk-management"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/55219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=55219"}],"version-history":[{"count":2,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/55219\/revisions"}],"predecessor-version":[{"id":56305,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/55219\/revisions\/56305"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=55219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=55219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=55219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}