Skip to content

customer penetration testing policy

0

One of my customers is about starting the pen testing.

Besides the pen testing policy that we need customer to follow, does customer need to inform AWS prior of conducting the pen testing?

AWS

asked a year ago387 views

2 Answers
5

Yes we are permitted to conduct penetration testing on their AWS-hosted infrastructure without prior approval, provided the testing is limited to AWS-designated permitted services. However, specific activities such as Command and Control (C2) testing, Denial of Service (DoS) simulations, and Red/Blue/Purple Team exercises require explicit approval from AWS before they can be performed.

EXPERT

answered a year ago

0

Hey,

Hope you're keeping well.

For most AWS services listed in the penetration testing policy, customers can perform testing without notifying AWS, as long as they stay within the permitted activities. If the test involves restricted actions such as Denial of Service simulations, port flooding, or C2 testing, you must submit an approval request via the AWS Support Center before starting. Make sure the scope is limited to your own AWS resources, and review the policy carefully to avoid impacting other tenants or violating the AWS Acceptable Use Policy.

Thanks and regards,
Taz

answered 9 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.