What is a pen test?

A pen test, or penetration test in full, is a controlled security investigation. Researchers try to find vulnerabilities before malicious parties do.

A pen test is not a random attack. There are agreements about scope, permission, approach, reporting and due care. The researchers use techniques that attackers can also use, but with the aim of improving security.

In the Methodology for Information Security Research with Audit Value (MIAUW), we have extensively discussed a definition led by Mr. V.A. the Pous. This resulted in this definition:

‘An offensive security investigation to be carried out by our own personnel or third parties, which involves a controlled search for vulnerabilities in one or more secured network and information systems or parts thereof, which can be used to break into these systems and/or which can, without intention or autonomously, disrupt the data processing of the organization under investigation or otherwise have adverse consequences.’

Also read What is MIAUW?.