RE: International Penetration Testing Law (United Kingdom)

From: Greg (greg@hoobie.net)
Date: 05/24/02


From: "Greg" <greg@hoobie.net>
To: "Penetration Testers" <pen-test@securityfocus.com>
Date: Fri, 24 May 2002 17:58:22 +0100

Assuming a generic remote pen test, you will be dealing with the UK Computer
Misuse Act (1990). You will need written permission from the system owners
and a well defined scope which must also be agreed and signed off before you
start (but I guess that's the same everywhere.)

If client data is to be or may be exposed during the test you should also
consider the UK Data Protection Act which governs the handling of personal
data and the like.

Your engagement letter/contract may need to be re-worded if is designed for
use within the US. For instance, I don't beleive there is the concept of the
data protection act in the US although I'm not entirely sure about that one.

CMA 1990 : http://www.hmso.gov.uk/acts/acts1990/Ukpga_19900018_en_1.htm
DPA 1998 : http://www.hmso.gov.uk/acts/acts1998/19980029.htm

enjoy

Greg

> -----Original Message-----
> From: M W [mailto:crackthis22@hotmail.com]
> Sent: 22 May 2002 23:12
> To: crackthis22@hotmail.com
> Subject: International Penetration Testing Law (United Kingdom)
>
>
> Does anybody have any insight (website/links) as to laws/restrictions on
> international pen testing, specifically from the United States to
> a client
> in the United Kingdom?
>
> Thanks in Advance
>
> _________________________________________________________________
> Join the world’s largest e-mail service with MSN Hotmail.
> http://www.hotmail.com
>
>
> ------------------------------------------------------------------
> ----------
> This list is provided by the SecurityFocus Security Intelligence
> Alert (SIA)
> Service. For more information on SecurityFocus' SIA service which
> automatically alerts you to the latest security vulnerabilities
> please see:
> https://alerts.securityfocus.com/
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: Using ARP to map a network
    ... On a HUB there would be absolutely no reason to send out ARP replies, ... >> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... > automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • RE: Password HTML form bruteforce
    ... print Positive Authentication with Login: ACCOUNT, ... >> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • RE: SQL Injection - retrieving all rows
    ... If you can GET responses from a SQL database just invoke the ASP page many ... >> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... >automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • Re: Problems on the DOS-Prompt
    ... >Is there a list of all availible commands that can be used on nt and 2k ... >>> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... >>> automatically alerts you to the latest security vulnerabilities ...
    (Pen-Test)
  • RE: How to aggregate output of NMAP
    ... > This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)