NetKingdom owns this; and a targeting rule, because scope widened
Operator decision: whitehat is a NetKingdom facility, framed offensively - offence is how you find out, and a control is believed until someone tries it. Our own estate is one target among those we choose, not the only one. I had argued for the-custodian on independence grounds. The counter-argument is better: offensive security is security work and belongs with the security repo. The residual tension is real and recorded rather than argued away - NetKingdom now owns both the Tenancy Posture framework and the facility that tests conformance to it, which is NetKingdom assessing NetKingdom. The mitigation is that findings leave for risk-nexus under separate ownership rather than being resolved in place. Proportionate, not perfect, and worth revisiting if conformance findings start getting quietly closed. The reframe changes what this repo must guard against, and that is the substantial part of this commit. A facility that can be pointed at infrastructure we do not own is the single thing that could turn this repo from an asset into a liability, so the targeting rule is structural rather than cultural. No target without recorded authorization from whoever is responsible for it. Own estate in build mode has standing authorization; production needs its own, because the blast radius differs and so does the decision; anything we do not own needs written per-engagement authorization recorded here before a packet is sent. Three non-authorizations written down because each is a way teams talk themselves into it: a commercial relationship with the target, the target being publicly reachable, and believing the owner would obviously be fine with it. Unauthorized probing is criminal in most jurisdictions regardless of intent, and a white-hat facility that gets this wrong is an attacker with better paperwork. Two consequences. The authorization record is part of the finding - a report that cannot name what it ran under is not a finding, it is an incident. And scope creep during an engagement is prohibited: a probe that discovers an adjacent system stops at the boundary, because following the interesting thing is how an authorized test becomes an unauthorized one. Findings routing now forks. Our estate goes to risk-nexus and on to the owning repo. Any other target goes to that infrastructure's responsible party on the engagement's agreed terms, with risk-nexus still recording that it happened. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
77f574f50e
commit
0ce9f44ff9
3 changed files with 95 additions and 31 deletions
|
|
@ -1,6 +1,8 @@
|
|||
# whitehat-security
|
||||
|
||||
Automated white hat IT-security, pen-testing and isolation-probing.
|
||||
NetKingdom's offensive security facility. Automated white hat IT-security,
|
||||
pen-testing and isolation-probing — pointed at infrastructure we choose,
|
||||
including our own.
|
||||
|
||||
The estate's **adversarial evidence facility**: it attacks our own systems, on
|
||||
a schedule, to find out whether the security properties they claim are actually
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue