A senior auditor runs it, with B-52 underneath
The engagement belongs to a named Security Brigade auditor. They agree the scope with you, decide where the depth goes and own the report; the platform does the testing.
Everything the platform tests unattended, it tests here. The auditor’s time goes into the judgement rather than into the coverage.
When this is the one
Three engagements that ask for a person in charge
- 01 The scope is not a standard one
- An application whose business logic has to be understood before it can be attacked, an estate assembled out of acquisitions, or a target where deciding what to test is most of the work.
- 02 The report has a person attached to it
- A named auditor scoped the engagement and owns the output, so there is somebody who can account for what was tested, what was found and what was left alone.
- 03 The output is going into a filing
- Security Brigade signs under its CERT-In empanelment, and the auditor who ran the engagement is what makes that signature possible. The expert-verified model reaches the same place by a different route.
How one runs
Five steps, and the auditor is in the third
The step that distinguishes this model is not the first or the last. It is the one in the middle, where somebody reads what has come back while the engagement is still running.
-
Before anything runs
The auditor works the scope out with you
What the targets are, which of the eleven coverage classes belong in this engagement, and what the assessment has to answer by the end of it.
-
The testing
B-52 works the scope through the six phases
Discovery, planning, scanning, exploitation, reporting, QA — the same run the platform performs unattended, on the same classes, to the same depth.
-
The part that makes it this model
The auditor reads what came back and decides what happens next
Where the findings point somewhere the scope had not anticipated, the auditor is the one who decides the engagement goes there. That decision sits with a person from the first day rather than with a review at the end.
-
What you receive
A report the auditor owns, with the evidence unchanged
Every finding still arrives with the request, the response and the steps to reproduce it. That unit of evidence does not vary between models; who stands behind the document around it does.
-
Where it can go
Signable under Security Brigade’s CERT-In empanelment
The auditor was in the engagement from the start, which is the condition that signature depends on.
What the platform underneath brings to it
An engagement has a fixed number of hours in it, and the test set a real application generates is larger than those hours let one person work through. Underneath this model, that test set is worked through in full rather than sampled to fit the timebox.
So the auditor’s hours go somewhere else — into the scope at the start, into reading findings while they are still arriving, and into the report at the end.
The division of labour
Six decisions, and who makes each one
Choosing between this model and the verified one comes down to who decides, and when. Here, most of the deciding happens before and during the run rather than after it.
| The decision | Who makes it in this model |
|---|---|
| What is in scope, and what is left out of it | The auditor, with you, before anything runs. |
| Which of the eleven coverage classes the engagement uses | The auditor. Nothing is withheld from this model — the classes available here are the classes available in all three. |
| How the testing is actually carried out | The platform. Six phases, and a candidate is either proved by a working exploit or dropped before it can reach the report. |
| Whether a finding stands, and what it means for you | The auditor. |
| Whether the run may act on production, persist beyond the entry host, or touch live credentials and real customer data | You, in writing. The three approval gates are identical in every delivery model, and a human-led engagement does not waive them. |
| Who the report belongs to | The auditor who ran the engagement. Security Brigade signs the assessment under its CERT-In empanelment. |
Who decides what in a human-led engagement
What is in scope, and what is left out of it
- Who makes it in this model
- The auditor, with you, before anything runs.
Which of the eleven coverage classes the engagement uses
- Who makes it in this model
- The auditor. Nothing is withheld from this model — the classes available here are the classes available in all three.
How the testing is actually carried out
- Who makes it in this model
- The platform. Six phases, and a candidate is either proved by a working exploit or dropped before it can reach the report.
Whether a finding stands, and what it means for you
- Who makes it in this model
- The auditor.
Whether the run may act on production, persist beyond the entry host, or touch live credentials and real customer data
- Who makes it in this model
- You, in writing. The three approval gates are identical in every delivery model, and a human-led engagement does not waive them.
Who the report belongs to
- Who makes it in this model
- The auditor who ran the engagement. Security Brigade signs the assessment under its CERT-In empanelment.
The other two ways to run the same platform
Both test what this one tests. They differ in where the human sits, and in one case in whether there is one at all.