Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS-60] Add a "Prepare Your Pentest Team" page #74

Open
wants to merge 6 commits into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 3 additions & 5 deletions content/en/Getting started/What to Expect/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,9 @@ Our pentesters share what they've found before they write your report.
Now that you've done all the work needed to set up a pentest, you might be anxious for
results. Here's what you can expect:

1. Once you've finished setting up a pentest, select **Pentests** in the left-hand
pane. You should see your pentest listed, with an "In Review" label.
1. You should see a link to a Slack channel, dedicated for your pentest.
1. Add the colleagues of your choice to the Slack channel. Choose colleagues who can
benefit from direct communication with our pentesters.
<!-- see layouts/shortcodes/pentest-in-review.html for content -->
{{% pentest-in-review %}}

1. We'll select the best available testers before the start of the pentest. We need
at least 48 hours. (We may need more time, if you have limits on the pentesters that
we can use.)
Expand Down
3 changes: 1 addition & 2 deletions content/en/Getting started/checklist.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,5 +51,4 @@ Under the Asset tab, you can review:
Congratulations! If you're ready with your pentest, select
**Submit for Review**.

Once you do so, learn [what to expect after you create a
pentest](../what-to-expect).
Once you do so, learn about how you should [Prepare Your Security Team](../prep_security_team/).
28 changes: 28 additions & 0 deletions content/en/Getting started/prep_security_team.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
title: "Prepare Your Security Team"
linkTitle: "Prepare Your Security Team"
weight: 260
description: >
Help our pentesters test your asset.
---

{{% pageinfo %}}
Tell your security teams to be ready to help, and to assess pentest findings.
{{% /pageinfo %}}

You've reviewed the [Pentest Checklist](../checklist/). You've submitted the pentest
for review. Here's what you should do next:

<!-- see layouts/shortcodes/pentest-in-review.html for content -->
{{% pentest-in-review %}}

{{% alert title="Note" color="note" %}}
Be ready to respond to **Critical** findings, especially if they pose a significant risk.

Do not update your asset for other findings until the pentest is complete, as
that risks compromising our pentest work in progress.
{{% /alert %}}

Tell your team about the pentest. In rare cases, a pentest might disrupt service to an asset.

Now you can read about [Pentest Expectations](../what-to-expect/).
16 changes: 16 additions & 0 deletions layouts/shortcodes/pentest-in-review.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
1. Select **Pentests** in the left-hand pane. You should see your pentest listed, with an
"In Review" label.
1. You should see a link to the Slack channel, dedicated for your pentest.
1. Add the colleagues of your choice to the Slack channel. Choose colleagues who can benefit
from direct communication with our pentesters. They should also be ready to help pentesters
with questions such as:
- Access to your asset
- Changes such as IP addresses and URLs
- Status of your asset (such as a web app that's "down")

Typically, those colleagues may include:

- Developers
- Site Reliability Engineers
- Systems Administrators
- Security Engineers