MITRE ATT&CK.
The path is named in its techniques. The dataset release is pinned on the engagement, because identifiers change between releases.
01Governance
ScaryByte runs Kestrel inside a written programme. Law, the contract, the rules of engagement, and the signed authorisation outrank every document the programme writes about itself.
01Procedures
An engagement moves in this order. A step is not skipped because a pack, a quote, or a calendar entry looks complete.
The scoping pack is received, and the secrets check is run before it is filed. Opposing interests are looked for. Regulated regimes are read from the pack. A draft pack is not a date in the diary.
The pack is applied. A questionnaire, a service selection, or a quotation does not authorise the test.
Written authorisation is on file before any work outside the lab. Schedule S14 must name an instrument that is in place, and every item marked before activity must be resolved. A selection does not open the window.
The method packs for that scope are confirmed. A critical finding is notified under the rules of engagement, not at the end.
Each artefact is taken with its source and time, checked, and sealed before it is treated as the record.
A finding is scored and tied to the frameworks that are actually in scope. A framework that was not in scope is not invented onto the page.
A second reader is required before delivery when any finding is Critical, or when a regulated report will be shared as an attestation.
The recipient is verified. The file is redacted, then hashed. Raw evidence is not released unless the contract requires it.
The case is sealed. A shared platform is wiped and the wipe is verified. A dedicated platform is destroyed and is never given to another client.
Only the findings that were agreed, and only while the authorisation still holds.
A change of scope is asked for in writing, then authorised again before the work moves.
When a regime is named in the authorisation, that path is added. It does not replace the order above.
02Frameworks
Adopted means the programme uses that framework’s vocabulary. It is not a measure of depth, it does not mean ScaryByte certifies the customer, and it does not turn the readout into an attestation. A mapping is not a certificate.
These are the default language of a run. An engagement pins the edition it writes against.
The path is named in its techniques. The dataset release is pinned on the engagement, because identifiers change between releases.
The classic seven phases, as a spine.
The lifecycle of the test. The snapshot used is named on the engagement.
September 2008. The methodology reference for a NIST-flavoured test.
v3.1 by default. v4.0, specification 1.1 of 9 November 2023, when that vector is the one recorded. One version per severity table. The two are not mixed without saying which is which.
The weakness. The CWE Top 25 held for prioritisation is the 2024 list, and the year is stated. It is an aid, not a scope.
CSWP 29, 26 February 2024, including the Govern function. The language used when the readout turns to remediation.
A remediation aid, linked back to the technique. The release is named when a countermeasure is cited.
Used because the scope needs them. Not pasted onto every finding.
Threat modelling, before the engagement.
When the classic chain is not enough.
Investigations.
Optional, beside CWE.
Web risk categories. The 2021 list is the one treated as canonical. A 2025 English text is also held, and the engagement names which list it uses.
2023, for an API scope. The 2019 text is history, not the pin.
4.0.3, October 2021, for application verification. ASVS 5.0.0 exists. An engagement stays on 4.0.3 until the scope names another edition. The identifiers do not carry across.
v2.1.0, for mobile.
AI and machine-learning scopes. The release, and the model under test, are named. A matrix link is not an evaluation.
Version 8, as vocabulary, when the customer is aligned to CIS. This is not an Implementation Group assessment.
The 2022 edition is the reference point when the customer is aligned to ISO. This is a mapping, not a certification, and not a management-system audit.
Revision 5 is what is held. Release 5.2.0, August 2025, also exists, so an engagement names the revision it writes against.
Lite, for a major cloud scope.
Official ISO and PCI texts stay with their publishers. The programme keeps the path and the worksheets. A finding mapped to a requirement is not a scheme assessment.
v4.0.1, June 2024, when cardholder data is in scope. Mapping a finding does not complete a Self-Assessment Questionnaire.
When the statement of work includes an ASV scan. The external scan is treated as black box unless that programme says otherwise.
PIN Security Requirements v3.1 when keys are in scope. The engagement pins one version.
3-D Secure, payment software, or a questionnaire the customer already cites. Eligibility for an SAQ is never inferred.
Pinned for card financial messaging. The dialect the target actually speaks is recorded, not only the year the customer names.
Financial key management. The part and the year are pinned on the engagement.
Lite, and only for a SWIFT scope. The customer’s annual attestation version is the one cited. Control identifiers are not invented.
The regime in the authorisation is the one that is followed. Naming a law here is not legal advice.
Act 4 of 2013, with the 2018 Regulations. South African personal information.
Act 2 of 2000. A pointer, in the South African context.
Act 19 of 2020. The South African legal frame. Charging and complaint decisions stay with the customer.
Lite. A governance bridge, not a board report. King V applies to financial years beginning on or after 1 January 2026. Which code applies depends on that customer’s financial year.
Regulation (EU) 2016/679, where EU or EEA personal data is in scope.
Privacy-management vocabulary when the customer runs that system. Earlier language assumed the 2019 extension to 27001. The current published standard is ISO/IEC 27701:2025, which stands alone. The 2019 edition is not treated as 2025. The edition in scope is named.
Version 1.0. The privacy programme map, when that language is asked for.
The Security, Privacy, and Breach Notification Rules, where protected health information is in scope.
Trust Services Criteria, when that language is requested. A technical review is not an attestation, and this practice does not issue one.
How a weakness is received, handled, and told. The edition is pinned when the work is a disclosure programme.
Vulnerability disclosure.
Vulnerability handling, paired with 29147.
Incident management, with the operations procedure. The part and the year are pinned.
Optional, and only when a quantitative figure is asked for. The default remains likelihood by impact. A number needs stated inputs and stated uncertainty.
Critical, High, Medium, Low, and Info. The score is CVSS, and the version of the vector is recorded on the finding. v3.1 is the default. A customer’s own labels may be used in the readout. The vector stays on the finding.
A legal hold stops disposal. A third party’s system stays out of scope until that party has authorised the test in writing.
It is not an ISO statement of applicability, and it is not a control certificate. The signed authorisation remains the boundary.
