Use this planner to tie each test to a decision, an owner and evidence that a fix worked. Fill it in with the people who commission testing and the people who fix what it finds.
Use internal reference IDs here. Keep findings and evidence in your approved records.
Set the objective
By the next review, we need evidence to decide __________.
| Planning field | Your notes |
|---|---|
| Program owner and decision-makers | |
| Next review date | |
| Changes or decisions that need evidence | |
| Systems proposed for coverage, and exclusions | |
| Remediation owners and their capacity |
Sequence the work
Add one row per proposed test, and only when it has an owner and a reason. Windows are indicative, not agreed dates.
| Decision or question | Test and boundary | Window | Owner | Retest agreed |
|---|---|---|---|---|
Before confirming the order, check whether a release makes an earlier result less relevant, and whether open findings should be fixed before similar work is repeated.
Track each improvement
| Evidence field | Your notes |
|---|---|
| Reference and tested boundary | |
| What testing found, and when | |
| Change made, and who owns it | |
| Retest scope and date, or not agreed | |
| Status: open, fixed but not retested, or retested |
A closed ticket does not show that the attack path has changed. A retest confirms only what it exercised.
A program does not need every service. Targeted penetration testing answers questions about a defined system. Adversary simulation examines attacker reach and response across a scenario. CAOS (Continuous Adversary Operations Service) runs recurring, human-led red team operations, and an annual program rotates testing across twelve months.