01Governance

The programme.

ScaryByte runs Kestrel inside a written programme. Law, the contract, the rules of engagement, and the signed authorisation outrank every document the programme writes about itself.

01Procedures

The order of the work.

An engagement moves in this order. A step is not skipped because a pack, a quote, or a calendar entry looks complete.

  1. PROC-014

    Intake.

    The scoping pack is received, and the secrets check is run before it is filed. Opposing interests are looked for. Regulated regimes are read from the pack. A draft pack is not a date in the diary.

  2. PROC-025

    Scope.

    The pack is applied. A questionnaire, a service selection, or a quotation does not authorise the test.

  3. PROC-001

    Open.

    Written authorisation is on file before any work outside the lab. Schedule S14 must name an instrument that is in place, and every item marked before activity must be resolved. A selection does not open the window.

  4. PROC-019

    Run.

    The method packs for that scope are confirmed. A critical finding is notified under the rules of engagement, not at the end.

  5. PROC-002

    Seal.

    Each artefact is taken with its source and time, checked, and sealed before it is treated as the record.

  6. PROC-008

    Map.

    A finding is scored and tied to the frameworks that are actually in scope. A framework that was not in scope is not invented onto the page.

  7. PROC-012

    Review.

    A second reader is required before delivery when any finding is Critical, or when a regulated report will be shared as an attestation.

  8. PROC-003

    Deliver.

    The recipient is verified. The file is redacted, then hashed. Raw evidence is not released unless the contract requires it.

  9. PROC-004

    Close.

    The case is sealed. A shared platform is wiped and the wipe is verified. A dedicated platform is destroyed and is never given to another client.

  10. PROC-013

    Retest.

    Only the findings that were agreed, and only while the authorisation still holds.

  11. PROC-021

    Change.

    A change of scope is asked for in writing, then authorised again before the work moves.

When a regime is named in the authorisation, that path is added. It does not replace the order above.

  • PROC-005PCI DSS and ASV.
  • PROC-006HIPAA.
  • PROC-007GDPR.
  • PROC-011PoPIA.
  • PROC-016ISO 8583 messaging.
  • PROC-017ISO 11568 keys.
  • PROC-018OWASP ASVS.
  • PROC-024OWASP MASVS.
  • PROC-020Vulnerability disclosure.

02Frameworks

What the finding is mapped to.

Adopted means the programme uses that framework’s vocabulary. It is not a measure of depth, it does not mean ScaryByte certifies the customer, and it does not turn the readout into an attestation. A mapping is not a certificate.

On the engagement.

These are the default language of a run. An engagement pins the edition it writes against.

MITRE ATT&CK.

The path is named in its techniques. The dataset release is pinned on the engagement, because identifiers change between releases.

Cyber Kill Chain.

The classic seven phases, as a spine.

PTES.

The lifecycle of the test. The snapshot used is named on the engagement.

NIST SP 800-115.

September 2008. The methodology reference for a NIST-flavoured test.

CVSS.

v3.1 by default. v4.0, specification 1.1 of 9 November 2023, when that vector is the one recorded. One version per severity table. The two are not mixed without saying which is which.

CWE.

The weakness. The CWE Top 25 held for prioritisation is the 2024 list, and the year is stated. It is an aid, not a scope.

NIST CSF 2.0.

CSWP 29, 26 February 2024, including the Govern function. The language used when the readout turns to remediation.

MITRE D3FEND.

A remediation aid, linked back to the technique. The release is named when a countermeasure is cited.

When the surface calls for it.

Used because the scope needs them. Not pasted onto every finding.

STRIDE.

Threat modelling, before the engagement.

Unified Kill Chain.

When the classic chain is not enough.

Diamond Model.

Investigations.

CAPEC.

Optional, beside CWE.

OWASP Top 10.

Web risk categories. The 2021 list is the one treated as canonical. A 2025 English text is also held, and the engagement names which list it uses.

OWASP API Security Top 10.

2023, for an API scope. The 2019 text is history, not the pin.

OWASP ASVS.

4.0.3, October 2021, for application verification. ASVS 5.0.0 exists. An engagement stays on 4.0.3 until the scope names another edition. The identifiers do not carry across.

OWASP MASVS.

v2.1.0, for mobile.

MITRE ATLAS.

AI and machine-learning scopes. The release, and the model under test, are named. A matrix link is not an evaluation.

CIS Controls v8.

Version 8, as vocabulary, when the customer is aligned to CIS. This is not an Implementation Group assessment.

ISO/IEC 27001 and 27002.

The 2022 edition is the reference point when the customer is aligned to ISO. This is a mapping, not a certification, and not a management-system audit.

NIST SP 800-53.

Revision 5 is what is held. Release 5.2.0, August 2025, also exists, so an engagement names the revision it writes against.

CSA CCM.

Lite, for a major cloud scope.

Payment.

Official ISO and PCI texts stay with their publishers. The programme keeps the path and the worksheets. A finding mapped to a requirement is not a scheme assessment.

PCI DSS.

v4.0.1, June 2024, when cardholder data is in scope. Mapping a finding does not complete a Self-Assessment Questionnaire.

PCI ASV.

When the statement of work includes an ASV scan. The external scan is treated as black box unless that programme says otherwise.

PCI PIN.

PIN Security Requirements v3.1 when keys are in scope. The engagement pins one version.

PCI 3DS, SSF, and SAQ.

3-D Secure, payment software, or a questionnaire the customer already cites. Eligibility for an SAQ is never inferred.

ISO 8583:2023.

Pinned for card financial messaging. The dialect the target actually speaks is recorded, not only the year the customer names.

ISO 11568.

Financial key management. The part and the year are pinned on the engagement.

SWIFT CSP.

Lite, and only for a SWIFT scope. The customer’s annual attestation version is the one cited. Control identifiers are not invented.

Personal information.

The regime in the authorisation is the one that is followed. Naming a law here is not legal advice.

PoPIA.

Act 4 of 2013, with the 2018 Regulations. South African personal information.

PAIA.

Act 2 of 2000. A pointer, in the South African context.

Cybercrimes Act.

Act 19 of 2020. The South African legal frame. Charging and complaint decisions stay with the customer.

King IV.

Lite. A governance bridge, not a board report. King V applies to financial years beginning on or after 1 January 2026. Which code applies depends on that customer’s financial year.

GDPR.

Regulation (EU) 2016/679, where EU or EEA personal data is in scope.

ISO/IEC 27701.

Privacy-management vocabulary when the customer runs that system. Earlier language assumed the 2019 extension to 27001. The current published standard is ISO/IEC 27701:2025, which stands alone. The 2019 edition is not treated as 2025. The edition in scope is named.

NIST Privacy Framework.

Version 1.0. The privacy programme map, when that language is asked for.

HIPAA.

The Security, Privacy, and Breach Notification Rules, where protected health information is in scope.

SOC 2.

Trust Services Criteria, when that language is requested. A technical review is not an attestation, and this practice does not issue one.

Disclosure.

How a weakness is received, handled, and told. The edition is pinned when the work is a disclosure programme.

ISO/IEC 29147.

Vulnerability disclosure.

ISO/IEC 30111.

Vulnerability handling, paired with 29147.

ISO/IEC 27035.

Incident management, with the operations procedure. The part and the year are pinned.

FAIR.

Optional, and only when a quantitative figure is asked for. The default remains likelihood by impact. A number needs stated inputs and stated uncertainty.

Severity.

Critical, High, Medium, Low, and Info. The score is CVSS, and the version of the vector is recorded on the finding. v3.1 is the default. A customer’s own labels may be used in the readout. The vector stays on the finding.

What is refused.

A legal hold stops disposal. A third party’s system stays out of scope until that party has authorised the test in writing.

What this page is not.

It is not an ISO statement of applicability, and it is not a control certificate. The signed authorisation remains the boundary.

05Developer

Kestrel.icu is developed by ScaryByte.

Contact ScaryByte
ScaryByte
Loading Kestrel.icu