Status and Details

Status and Details

This page contains information about the status, approval and implementation of this document, contact details for the relevant Manager and Policy Author and, on the right, a brief summary of changes between this and the previous version.
 

Penetration Testing Policy

Show Field Notes
Status Current
Effective Date 26th June 2026
Review Date 26th December 2028
Approval Authority Director
Approval Date 26th June 2026
Expiry Date Not Applicable
Responsible Manager Joanne Auld
Director
Author Joanne Auld
Director
Enquiries Contact Joanne Auld
Director

Summary of Changes from Previous Version

Information security depends not only on implementing appropriate controls, but also on periodically validating that those controls remain effective in protecting our information, information assets, products and services. Penetration tests provide independent assurance that vulnerabilities are identified, understood and addressed before they can be exploited.

This Policy sets out our commitment to conducting penetration tests in a controlled, responsible and proportionate manner that strengthens our information security while protecting the confidentiality, integrity and availability of our information, information assets, products and services.

Clauses Amended:Policy: All