5 ms·
Here's the scoping doc: https://iowacourts.gov/static/media/cms/Rules_of_Engag_E9D807B3D13D3.pdf https://iowacourts.gov/static/media/cms/Rules_of_Engag_E9D80...
by sullivanmatt 7y ago
Here's the scoping doc:
https://iowacourts.gov/static/media/cms/Rules_of_Engag_E9D807B3D13D3.pdf https://iowacourts.gov/static/media/cms/Rules_of_Engag_E9D80...
Some highlights include authorization to attempt entry by tail gating, lock picking, place devices once access has been gained, etc. It's a total vindication for Coalfire (IMO).
- nekoashide 7y agoThey specifically stated that this access would only be between 6AM and 6PM MST or "Normal Business hours". Not seeing anything that's allowing them outside of these hours.
- alteria 7y agoWhich is interesting since they said that the physical pentesting could be "during day and evening," but you're right. Haven't seen anything affirmatively allowing them to conduct outside of 6am-6pm MST. They DID have permission to lockpick, and maybe the state asked for testing after 6pm MST but hasn't released the request (per the blurb below) "Requests for testing outside this time period outside the above may result in additional charges per the terms of the MSA"
- foota 7y agoI felt like that was more about billing than limiting the scope, but you're right that there's seemingly a conflict.
- scrumper 7y ago"Expected to be" is not the same as "will only be", and that's the sort of thing that gets decided by a judge. (The existence of the additional charges language does weaken that argument a bit since if "expected to be" really was meaning that things could happen outside of those hours, then you wouldn't need to reference those MSA terms.) IANAL, but have written more than my share of SOWs and contracts of this type. Drafters tend to always default to the position of greatest optionality for them. Hence, "expected to be".
- jcims 7y agoI don't know about total vindication. They may have had all the right things on paper (TBD), but someone could easily have easily been killed and I imagine their SOP will change after this.
- mike_d 7y agoPage 3, the scoping section clearly lists the three addresses where physical testing would take place. Page 5 also lists it on the timeline, which based on other notes about not testing specific days - the client would have absolutely reviewed. Page 12 is a client questionnaire where they answer physical security questions. People do get arrested doing this type of work. It hasn't happened to me, but it has happened to people I know. Usually it is quickly and quietly resolved without the press being involved. What I believe is at issue here is authority. Can a state entity authorize testing of county buildings? Some people just assume "the government" is one entity. This same type of issue arises in corporate work as well - can a tenant authorize testing against a landlords building? You need to get both to agree. (Disclaimer: I do this type of work so I might be biased)
- kerng 7y agoPentesters sometimes are leveraged as pawns in political games in organizations - seems similar with government. I think you are correct, the question is if the right stakeholders authorized this. You can't break into a 7/11 because some person working there authorized it. Authorization needs to be from all proper stakeholders.
- alteria 7y agoIf this is true, is it Coalfire's fault for not verifying and are the two testers SOL with the burglary charge? Then is it also the fault of the two testers in this case that they too did not verify that all the correct stakeholders were brought in? It would suck to be in the position of the testers having little or no recourse.
- iforgotpassword 7y agoI'm very hesitant to blame the two individuals. While you should have basic understanding of the legal circumstances when working this job, you should be able to trust your higher ups that the paperwork is legit and thorough. A company the size of coalfire certainly has dedicated personnel just for dealing with that.