For the complete documentation index, see llms.txt. This page is also available as Markdown.

🖥️Preparing your environment for the testing team

Preparing your testing environment and the differences between testing on staging versus production.

When preparing an environment for the penetration test, ensure that it mirrors your production environment as closely as possible and accurately represents normal operating conditions for a typical user or customer.


Test environment requirements

The following requirements help Software Secured ensure the best possible coverage of the test:

  • All features that are used for the most common use cases or workflows are fully enabled, configured, and licensed on the environment.

  • All known differences between the test and production environment are highlighted during the kickoff call.

  • If the system has known integrations with other external systems, Software Secured might need access or testing equivalents of those to ensure that we can test for any risks posed by the integration points and any associated data flows into the system.

  • If a web application firewall (WAF), intrusion prevention system (IPS), or other security appliance is in use, they either need to be disabled, or the IP addresses of the testers need to be given access permission through your network's allowlist (or whitelist).

    • Software Secured’s IP addresses are included in the pentest checklist. For more information, see Pentest checklist.

  • The test environment must be consistently available throughout the test dates until final report delivery. This access supports the report writing, evidence collection, and our quality assurance process. Once the report is delivered, the environment can be de-provisioned if needed.

These requirements help Software Secured ensure the best possible coverage of the test.

If you wish to test the effectiveness of these controls, ask us about other test offerings such as red teaming and cloud security reviews.


Testing the production environment

Any network or infrastructure pentests are conducted on the production environment.

For all other test portions—such as application or software— Software Secured's best practice is to test on a staging or a test environment.

Pentesting an application in a production environment is possible; however, pentesting by design is an invasive process and tests come with risks for outages or data deletion. When focusing solely on the network, these risks are less of a concern compared to when data or availability can be compromised.

For more information about the advantages and disadvantages of testing on production, see 15 Risks & Rewards of Pentesting in a Production Environment.

Last updated

Was this helpful?