This conversation simply explains how MIAUW works and what the added value is. It is a clear summary, which is of course not comprehensive. It discusses the why, how MIAUW works and why you need clarity about the tests.

In addition, it discusses well the audit value with the use of an auditor.

We have created a transcript of the conversation:

Speaker 1 Hello and welcome today we dive into the world of penetration testing. They are often called pen tests. You know how important cybersecurity is, right? Especially with new legislation such as, well, NIS2, which increases the pressure.

Speaker 2 Certainly, but you sometimes wonder about that pen test that I had done. Was that really good, you know? And what do those results actually mean?

Speaker 1 Exactly. And that, that is precisely what the sources that we have, especially those parts of pentesting, are trying to address, according to meauw. Yes, that is quite a mouthful for methodology for information security research with audit value, but the idea is to create order. Well, sometimes a somewhat opaque world.

Speaker 2 OK, so get rid of that ambiguity, the goal today is to see what the miauw methodology entails and why such a structured approach is apparently so important to really be in control. Let’s unpack that.

Speaker 1 Good idea. The sources actually start with practical examples, things that go wrong, right? Yes.

Speaker 2 For example, reports that you are not allowed to inspect, tests that simply skip important systems, or findings that later turn out not to be correct at all.

Speaker 1 Em your is a kind of response to the core idea. Make sure everything is imitable and irrefutable. Every investigation must, as they say, have audit value.

Speaker 2 Audit value that sounds serious. What exactly does that mean?

Speaker 1 Nou, het betekent gewoon dat glashelder is. What you have investigated, how you did that and with what result and very importantly, with all the evidence, you have defined 9 certainties, such as clarity about the expertise of the tester, the process that was followed or whether the test was complete according to standards.

Speaker 2 Wait a minute according to standards. Yes, the scope must be clear, the evidence and reporting must be uniform. It’s quite a list.

Speaker 1 It sounds like miauw, not so much reinventing the wheel, but more taking existing best practices and standards and saying, this is how it should be done, correct?

Speaker 2 Yeah, that’s a good summary actually. The sources specifically mention international standards, such as the Owasp test guides.

Speaker 1 Oh well, I know him from the top.

Speaker 2 Exactly, but pay attention, right? The source emphasizes look beyond those top ten. That’s more for awareness. Not a complete test method. These are the real guides. Pstg for web MSTG for mobile and so on.

Speaker 1 How do they determine the clarity and seriousness of what is found?

Speaker 2 For this purpose, MIAUW prescribes the CV SS standard, which gives a score from zero to 10. That helps to make it objective, you know?

Speaker 1 Logical.

Speaker 2 By the way, they also mention CIS controls for configuration checks, but, which is important, if something does not comply with such a CIS control, it is not automatically a vulnerability with a CV. Traces, That’s more of an observation, context is important there.

Speaker 1 OK so standards for the content, but what about the process? That probably needs to be tighter too.

Speaker 2 Absolutely, that is also structured. It starts with an intake, a pre-engagement phase. Then you will receive an action plan.

Speaker 1 A plan of action? Yes.

Speaker 2 Then the implementation itself and then the completion and reporting, but the icing on the cake with miauw is an optional step. Validation by an independent auditor.

Speaker 1 Wait for an auditor to watch a pen test. That’s new to me. How does that work?

Speaker 2 The auditor sets up a process renovation that checks. Actually, all those requirements have been met. Has the process been followed? As agreed, is the evidence really there? Is the reporting correct?

Speaker 1 Ah, so he checks the controllable, so to speak.

Speaker 2 Exactly, that is the key to that audit value. That auditor is less concerned. The technical depth. That remains the role of the penetration tester, but it really concerns the reliability of the entire process.

Speaker 1 And that of course helps enormously to demonstrate that you are in control of NS and the GDPR. 70 10 In healthcare.

Speaker 2 Right, that’s the idea, demonstrability.

Speaker 1 Logically and the legal side is also taken into account, because yes, testing without permission is punishable, right? Computer breach.

Speaker 2 That’s right, the sources are clear about that. Good agreements about the scope are crucial. A non-disclosure agreement an NDA is standard disclaimers as well.

Speaker 1 And GDPR if they encounter personal data.

Speaker 2 Yes, then a processing agreement is often necessary, according to the sources. So you see all those things together, the methodology, the standards, that official report, the legal framework, making your pen test really more than just a technical test.

Speaker 1 It becomes a kind of piece of evidence.

Speaker 2 A verifiable piece of evidence of due care? Yes. OK so in summary, miauw tries to make pen testing, well, more transparent, more consistent and, above all, demonstrably reliable. It gives you a kind of framework, so that you know what you are buying and that the results actually have value for audits and compliance.

Speaker 1 It provides something to hold on to so that you can really show yourself. Look, we take this seriously, we control it, We are in control.

Speaker 2 Well, one last thought then, eh? When we look at those sources. Now that pressure to be demonstrably in control. This increases the technical and legal process. How does that change? The way in which you, as an organization, purchase such a pen test is a good question, is the lowest price still the most important or does demonstrable quality become the audit value we were talking about? I think it’s a much more important thing to think about.