Before any penetration testing begins — especially in a complex IT infrastructure involving multiple systems, cloud environments, and potentially shared platforms — a formal written authorization from the customer (client organization) is mandatory.
This authorization defines the scope, targets, timeframes, and limitations of the assessment and ensures legal protection for both the tester and the organization. Conducting testing without explicit client authorization could violate laws (e.g., Computer Fraud and Abuse Act in the U.S.) and corporate policies.
Why not the others:
B. Penetration tester authorization: The tester cannot authorize their own actions; authorization must come from the system owner.
C. Third-party authorization: Only relevant if the third party owns the infrastructure; otherwise, it’s not mandatory.
D. Internal team authorization: Internal teams may coordinate logistics, but legal authorization must come from the customer/asset owner.
CompTIA PT0-003 Objective Mapping:
Domain 1.0: Planning and Scoping
1.2: Explain legal concepts, authorization requirements, and rules of engagement prior to testing.