OPERATIONAL SECURITY
"Also be aware that local groups may not be able to accurately gauge the safety of their
communications with you. Sometimes they underestimate the likelihood of risk - at other
times, they can wildly overestimate the risk. Either way, trainers need to navigate this issues
carefully and respectfully with a "do no harm" approach that respects the reported needs,
context, and experiences of your local contact and potential trainees." - Needs Assessment:
Level-Up 1
SUMMARY
Below are the baseline operational security guidelines for a SAFETAG audit. Activity specific
operational security guidelines are contained within each activity.
PURPOSE
An audit uncovers an array of sensitive information about an organization. For some at-risk
populations the mere act of getting a digital security audit can increase their likelihood of
being actively attacked by an adversary. The foundation of the SAFETAG process is the goal
of increasing the safety of the host organization, its staff, and the auditor. It is vital that an
auditor weigh the possible risk and audit may incur on the organization or the auditor
against the possible outcomes of an audit.
OBJECTIVES
Data storage security
Keep ALL data related to the audit secured per thePentest Standards for data
security, from interview and research notes through audit findings and
reporting outputs. Additional notes per section.
Communications security
Conduct all communication with the client over at least minimally secure
channels where the communication is encrypted in transit at all times per the
Pentest Standards for data security.
Higher levels of security (such as PGP, truecrypt, or minilock) should be used
for all file and document transfers.
Page 11 of 240