~/appsecaudit/process.txt
Process
From first call to verified fixes.
- CALL
- SCOPE
- SIGN
- TEST
- DELIVER
- RE-TEST
0x01 / CALL
Start with context.
A short call establishes the application, objective, and constraints.
0x02 / SCOPE
Keep the target focused.
Define clear boundaries, access, prerequisites, and expected effort.
0x03 / AGREE
Remove ambiguity.
Confirm the scope and schedule, then sign the contract and NDA.
0x04 / TEST
Attack the real system.
Manual testing verifies, reproduces, and documents meaningful attack paths.
0x05 / DELIVER
Make findings usable.
Evidence, impact, and remediation arrive in formats engineers can act on.
0x06 / RE-TEST
Verify the fixes.
A focused follow-up can validate remediation now or in a later assessment.
// OUTPUT
- Complete report for review and distribution.
- MARKDOWN
- Portable report source without platform lock-in.
- FINDINGS
- Individual Markdown files ready for Jira or other issue trackers.
- REVISIONS
- Internal, auditor, customer-facing, or redacted editions.
0xFE / FOLLOW-UP
Re-test when ready.
Order a focused follow-up after remediation - or return later to confirm that important controls still hold.