Qualify the objective
Define the decision, critical services, stakeholders, operating context, and the question the engagement must answer.
TRANSITION / LOADING
Preparing the next reviewable route and its evidence boundary.
Public boundary. This transition does not request credentials, payment details, or private incident evidence.
METHODOLOGY / CONTROLLED ENGAGEMENT
A strong assessment is not only technically capable. It is authorized, bounded, explainable, evidence-aware, and useful to the people who must decide what happens next.
Defensive scope. ZeroDev does not perform unauthorized access, indiscriminate scanning, credential theft, persistence, evasion, malware delivery, or destructive activity.
// ENGAGEMENT LIFECYCLE
The lifecycle applies across penetration testing, risk reviews, due diligence, compliance readiness, resilience planning, and incident exercises.
Define the decision, critical services, stakeholders, operating context, and the question the engagement must answer.
Record ownership, written authorization, in-scope assets, exclusions, timing, contacts, and stop conditions.
Agree test methods, safety limits, rate boundaries, evidence handling, communications, and escalation before activity.
Use the least data necessary for the objective. Preserve source, timestamp, context, and uncertainty with the observation.
Separate scanner output, analyst observation, confirmed finding, business impact, exploitability, and residual uncertainty.
Deliver technical detail, executive meaning, owners, priority, remediation options, assumptions, and limitations.
Track remediation, retest changed controls, exercise recovery where relevant, and record what remains open.
Leave a reviewable evidence trail, lessons learned, next review date, and an explicit statement of what the work does not prove.
// CONTROL BASELINE
These controls are not decorative language. They are the minimum questions to resolve before an engagement is treated as ready to begin.
Written authorization and named decision owner
Defined scope, exclusions, timing, and stop conditions
Emergency contacts and escalation path
Data minimization and evidence-handling boundary
Clear distinction between observation and validated finding
Technical and executive reporting paths
Remediation ownership and retest criteria
Explicit limitations, assumptions, and residual risk
// RULES OF ENGAGEMENT STARTER
This synthetic starter shows the control questions to resolve before an authorized assessment, validation activity, or exercise. It keeps the technical method subordinate to authority, safety, evidence handling, and owner decisions.
Public boundary. The public starter is not an authorization, a target list, a test plan, or permission to access any system. The applicable contract, owner, security contact, and approved handling process control the real engagement.
| Control area | Record before activity | Pause or escalate when |
|---|---|---|
| 01Authority instrument | Owner, permission or contract reference, objective, named approver, and change authority. | The authority is missing, unclear, expired, or does not cover the proposed activity. |
| 02Target boundary | Assets, accounts, environments, dependencies, exclusions, source date, and ownership. | A target is outside the agreed boundary, unowned, or materially different from the approved scope. |
| 03Permitted methods | Test categories, validation depth, credential use, and whether social, physical, or other special activity is explicitly approved. | A method is not explicitly approved, or the activity would be destructive, unsafe, or outside the defensive objective. |
| 04Timing and safety | Test window, rate or volume limits, availability constraints, maintenance conflicts, safety contact, and stop conditions. | There is instability, unexpected impact, a safety signal, or no reachable safety contact. |
| 05Data and evidence | Minimum necessary data, redaction, storage and transfer channel, retention boundary, and evidence owner. | Sensitive, restricted, or unrelated data appears and the approved handling path is not confirmed. |
| 06Communications and escalation | Routine reporting, emergency route, incident distinction, and named decision points. | A live incident, material impact, or uncertainty requires an owner decision or approved escalation. |
| 07Closeout and cleanup | End time, access removal, temporary-change reversal, artifact handling, validation, limitations, and retest condition. | Access, temporary change, artifact, or unresolved effect cannot be reconciled at closeout. |
| 08Change control | How scope, timing, methods, contacts, and exceptions are approved and recorded. | A material change is requested without the authority owner’s approval and an updated record. |
// RISK INTERPRETATION
A finding becomes useful when its consequence, exposure, exploitability, control strength, evidence confidence, and urgency are visible to the people who own the decision.
Potential treatment choices include remediate, mitigate, transfer, avoid, accept with a named owner and time boundary, or monitor and retest. A rating supports prioritization; it does not replace contract, legal, safety, classification, or owner judgment.
Mission consequence — effect on a critical service, safety objective, obligation, or decision
Exposure — reachability, dependency, affected population, and operating conditions
Exploitability — effort, access, capability, prerequisites, and plausible attack path
Control strength — prevention, detection, response, recovery, and compensating measures
Evidence confidence — source quality, recency, verification method, and unresolved uncertainty
Urgency — change window, threat context, contractual date, or decision that makes timing material
// EVIDENCE OUTPUTS
Before an output becomes a public capability or trust statement, compare its evidence state, owner, and limitations against the claims-to-proof matrix .
Decision, risk, owner, treatment choices, residual risk, and the next review date.
Scope, evidence, observation-versus-finding distinction, severity, limitations, and remediation detail.
Requirement, control, owner, evidence, gap, exception, status, and the next review or test date.
Critical service, dependencies, RTO/RPO assumptions, exercise result, recovery gap, and next validation.
// CONTINUE
Review the service areas, standards library, or remediation lifecycle before starting a conversation.