← Back to Home

Disclaimer

These templates are a starting point. Have them reviewed by a qualified Australian solicitor before use. This is not legal advice.

Australian Law Summary

Criminal Code Act 1995 (Cth) - Part 10.7

Key Protection: Written authorization from the system owner is your defense. The difference between a penetration test and a crime is a signed scope document.

1. Authorization to Test

The critical document. Without it, you have no defense.

Authorization to Conduct Security Testing

1. Parties
Client:
ABN:
Representative:
Position:

Tester: 22nd Survey Division
ABN: 50 692 429 397
Contact: [email protected]

2. Authorization

The Client authorizes the Tester to conduct security testing against the Target Systems specified below.

The Client confirms they have the legal right to authorize this testing and that all required third-party permissions have been obtained (e.g., cloud provider authorization).

3. Scope - Target Systems

In-Scope IP Addresses/Ranges:

In-Scope Domains:

Out-of-Scope (DO NOT TEST):

4. Testing Window
Start:
End:
Timezone: Australia/
5. Testing Types Authorized
  • External Network Penetration Testing
  • Internal Network Penetration Testing
  • Web Application Testing
  • API Security Testing
  • Social Engineering (Phishing)
  • Red Team / Adversary Simulation
6. Rules of Engagement

The Tester WILL:

  • Operate only within the defined scope
  • Stop immediately if requested
  • Report critical vulnerabilities immediately
  • Maintain confidentiality

The Tester WILL NOT:

  • Test systems outside scope
  • Conduct DoS attacks (unless authorized)
  • Access real customer data
  • Install persistent backdoors
7. Emergency Contacts
Client Contact:
Phone:
8. Signatures
Client Authorized Representative
Signature:
Name:
Date:
Tester (22nd Survey Division)
Signature:
Name:
Date:

2. Non-Disclosure Agreement

Protects both parties' confidential information.

Mutual Non-Disclosure Agreement

Parties
Party A:
ABN:

Party B: 22nd Survey Division (ABN 50 692 429 397)

Purpose

Exchange of confidential information for security assessment and penetration testing services.

Confidential Information Includes
  • Security vulnerabilities discovered
  • Network architecture and configurations
  • Source code and documentation
  • Customer data encountered during testing
  • Testing methodologies and tools
Obligations
  • Keep information strictly confidential
  • Use only for the stated purpose
  • Not disclose to third parties
  • Return or destroy upon request
Term
Agreement Term: years
Confidentiality Survives: years
Governing Law: , Australia
Signatures
Party A
Signature:
Name:
Date:
Party B (22nd Survey Division)
Signature:
Name:
Date:

3. Limitation of Liability

Include in your Master Service Agreement.

Liability & Disclaimer Clauses

Client Acknowledges
  • Penetration testing may cause disruption
  • No assessment guarantees discovery of all vulnerabilities
  • Security testing is point-in-time
Client Responsibilities
  • Valid authorization for all Target Systems
  • Backup all systems before testing
  • Notify third parties (hosting, cloud providers)
  • Incident response procedures in place
Limitation of Liability

Total liability shall not exceed the fees paid under the engagement.

Tester not liable for indirect, incidental, or consequential damages, loss of profits, or business interruption.

Indemnification

Client indemnifies Tester against claims arising from testing conducted within authorized scope.

4. Cloud Provider Requirements

Notification Requirements

AWS: No pre-approval needed for most testing. Prohibited: DNS zone walking, DoS, port flooding.

Azure / M365: No pre-approval needed. Must comply with Rules of Engagement.

Google Cloud: No notification required for your own resources.

Shared Hosting / VPS: ALWAYS notify the provider. Get written confirmation.