Penetration testing methodology
Findings that name the control, not just the CVE.
Our testing follows NIST SP 800-115 and, where the system is pursuing or holding a cloud authorization, the FedRAMP penetration testing guidance and its required attack vectors. That matters: a test scoped to a generic methodology often fails to satisfy the specific requirement your assessment is measured against.
Most technical reports are written for engineers rather than for assessors. The result is a scan export nobody can map to a control, and a POA&M assembled by hand weeks later.
DASATECH performs the testing and writes the findings the way the assessment process needs them: risk-rated, mapped to the affected control, with a remediation recommendation specific enough to act on and a retest path defined.
Testing is scoped and authorized in writing before anything begins, with rules of engagement agreed with your team.
- External and internal network penetration testing
- Web application testing aligned to the OWASP Top 10
- API and web service testing
- Cloud configuration testing across Azure, AWS and GCP
- Social engineering, including phishing and pretext campaigns
- Authenticated and unauthenticated vulnerability assessment
- Secure configuration review against DISA STIGs and CIS Benchmarks
- Retest and closure validation of remediated findings
Example values. Closure evidence is produced as part of the engagement and drops into your POA&M.
How it runs
Engagement sequence
Scoping and authorization
Targets, test windows, escalation contacts and rules of engagement are documented and signed before testing begins.
Discovery
Asset and service enumeration to confirm the scope matches the environment as it actually exists.
Testing
Vulnerability assessment, configuration review and manual testing, with critical findings reported immediately rather than held for the report.
Reporting
Findings are risk-rated, mapped to controls and written with remediation guidance a system owner can execute.
Retest
Remediated findings are validated and closure evidence is produced for the POA&M.
Deliverables
Test outputs
Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.
- REPORTTechnical findings report with risk ratings and evidence
- SUMMARYExecutive summary written for non-technical decision makers
- ROERules of engagement and authorization record
- MAPFindings mapped to affected security controls
- POA&MPOA&M-ready finding export with remediation recommendations
- RETESTClosure validation report for remediated items
Outcome
Why this version of a pen test is different
- Findings arrive already mapped to the controls your assessment will test
- Critical issues are escalated during testing, not disclosed in a report weeks later
- Remediation guidance is specific to your platform and configuration
- Retest and closure evidence is part of the engagement, not a new one
- The output drops into a POA&M without translation
Tell us what the contract requires. We’ll tell you what it takes.
A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.
