A
ACE CYBER DEFENSE AUTHORIZATION POLICY
AUTHORIZATION-FIRST

Written authority before active testing.

Ace Cyber Defense operates on an authorization-first basis. A public request is an inquiry only.

Before an assessment begins

Ace Cyber Defense requires confirmation of ownership or documented authority for the systems being assessed.

The engagement must establish:

  • Authorized systems and assets
  • Permitted testing methods
  • Excluded systems and techniques
  • Permitted testing dates and times
  • Emergency contacts
  • Evidence-handling expectations
  • Stop conditions and escalation procedures

Required documentation

Depending on the engagement, documentation may include a Statement of Work, Client Authorization, Rules of Engagement, and related contractual terms.

Fail-closed principle

If authorization or scope is unclear, active testing does not proceed until the uncertainty is resolved.