Security Testing Authorization Templates
These templates are a starting point. Have them reviewed by a qualified Australian solicitor before use. This is not legal advice.
Criminal Code Act 1995 (Cth) - Part 10.7
Key Protection: Written authorization from the system owner is your defense. The difference between a penetration test and a crime is a signed scope document.
The critical document. Without it, you have no defense.
Tester: 22nd Survey Division
ABN: 50 692 429 397
Contact: [email protected]
The Client authorizes the Tester to conduct security testing against the Target Systems specified below.
The Client confirms they have the legal right to authorize this testing and that all required third-party permissions have been obtained (e.g., cloud provider authorization).
In-Scope IP Addresses/Ranges:
In-Scope Domains:
Out-of-Scope (DO NOT TEST):
The Tester WILL:
The Tester WILL NOT:
Protects both parties' confidential information.
Party B: 22nd Survey Division (ABN 50 692 429 397)
Exchange of confidential information for security assessment and penetration testing services.
Include in your Master Service Agreement.
Total liability shall not exceed the fees paid under the engagement.
Tester not liable for indirect, incidental, or consequential damages, loss of profits, or business interruption.
Client indemnifies Tester against claims arising from testing conducted within authorized scope.
AWS: No pre-approval needed for most testing. Prohibited: DNS zone walking, DoS, port flooding.
Azure / M365: No pre-approval needed. Must comply with Rules of Engagement.
Google Cloud: No notification required for your own resources.
Shared Hosting / VPS: ALWAYS notify the provider. Get written confirmation.