# Osolix · External Penetration-Test Engagement Pack

> **Owner:** CISA Manager (IT Audit, Risk & Compliance)
> **Sponsor:** CTO + Group CFO
> **OKR target:** 2026-Q3 KR-2.1 — pass an external penetration test with zero critical findings
> **Engagement budget:** AED 80K — 150K (depending on vendor + scope days)
> **Engagement window:** 4 calendar weeks (1 prep · 2 testing · 1 remediation + retest)

This pack is everything an external pen-test vendor needs to engage Osolix
against the SOX 404 control matrix. It bundles scope, success criteria,
vendor selection rubric, pre-engagement hygiene, and the post-engagement
remediation discipline. The CISA Manager owns this file end-to-end.

---

## §1 · Scope (what's in)

### 1.1 In-scope production surface

| Surface | Endpoints / artefacts | Test depth |
|---|---|---|
| **Web application — frontend** | All pages under `/dashboard`, `/assets`, `/maintenance`, `/admin/*` rendered by the React + TypeScript SPA | OWASP ASVS L2 |
| **REST API — backend** | Every controller under `Osolix.Api/Controllers/` (~124 controllers, ~600+ endpoints) | OWASP API Security Top 10 (2023) |
| **SSO authentication flow** | OIDC code flow (Microsoft Entra · Google · Okta · Generic) at `/api/auth/sso/*`; SAML 2.0 SP-Initiated at `/api/auth/sso/{id}/saml/*` | NIST SP 800-63-3 IAL2/AAL2 |
| **SCIM 2.0 surface** | `/scim/v2/*` (Users + Groups CRUD, ServiceProviderConfig discovery) | RFC 7644 + SCIM-specific abuse cases |
| **ERP inbound webhooks** | `/api/erp-inbound/{token}/*` (anonymous bearer + optional HMAC) | Replay, signature wrapping, IP-allowlist bypass |
| **AI co-pilot endpoints** | `/api/invoice-copilot/*`, `/api/asset-classifier-copilot/*` (online + offline + hybrid) | Prompt injection, jailbreak, data exfiltration via prompts |
| **File upload paths** | Smart Invoice Wizard PDF/PNG, asset photos, document attachments | Magic-byte spoofing, polyglot files, ZIP-bomb, malware |
| **Background workers** | ERP outbox dispatcher, depreciation auto-run, PM scheduler, alert dispatcher, approval escalation | Side-channel via outbound HTTP, configuration tampering |
| **Database tier (out-of-band review)** | EF migrations + schema audit; SQL-injection regression on every `IQueryable` chain | Fuzz harness over the top-50 endpoints |
| **Infrastructure** | TLS configuration, header hardening (CSP / HSTS / X-Frame-Options), DataProtection key chain, JWT signing key rotation | Mozilla Observatory ≥ A grade |

### 1.2 Out of scope (explicit)

- **Anthropic API and Ollama runtime** — these are third-party / customer-hosted. Tested only at the boundary (Osolix's prompt construction + response handling).
- **Customer ERP systems** (Oracle Fusion / SAP / Dynamics / Odoo) — Osolix only tests the integration surface, not the ERP itself.
- **Physical security** of the cloud / on-prem hosting — handled separately under the cloud provider's compliance contract.
- **Social engineering / phishing of Osolix staff** — handled separately under the annual security-awareness review.
- **Denial-of-service load testing** beyond the `RateLimiter` configuration verification — explicitly excluded; tested separately under capacity planning.

### 1.3 Acceptable testing techniques

✅ Authenticated + unauthenticated black-box web scan
✅ Manual + automated API testing (Burp Pro · OWASP ZAP · Postman)
✅ SQL-injection fuzz over the top-50 endpoints
✅ XSS / CSRF / SSRF probe per OWASP ASVS L2
✅ JWT manipulation (algorithm confusion, signature stripping, claim tampering)
✅ SAML signature-wrapping + assertion replay
✅ OIDC state / nonce / PKCE bypass attempts
✅ SCIM token brute-force + IP-allowlist bypass
✅ AI prompt-injection sweeps with the OWASP LLM Top 10 (2024) checklist
✅ TLS / header / cookie review

⛔ No actual customer data exfiltration (use synthetic Demo tenant only)
⛔ No persistent backdoors or implants
⛔ No DDoS or volumetric abuse
⛔ No probing of out-of-scope third-party services

---

## §2 · Success criteria

The engagement passes if and only if **all five** of these are true on the final report:

1. **Zero critical findings** (CVSS ≥ 9.0 or any "remote unauthenticated RCE / data dump" classification)
2. **Zero serious findings** that remain unmitigated 30 days after report delivery
3. **All medium findings** have a documented owner + remediation timeline ≤ 90 days
4. **Mozilla Observatory** score on the production frontend ≥ A
5. **OWASP API Security Top 10 (2023)** — zero category-level failures

The CISA Manager signs the engagement-close letter only after items 1-3 are met.

---

## §3 · Vendor selection rubric

The following four vendors are pre-qualified by the CISA Manager. Final selection is by competitive bid + reference-check on at least two recent SaaS engagements.

### 3.1 Hard requirements (any vendor must satisfy all)

- ✅ **Recognised certification on the lead consultant**: OSCP / CREST CRT / GIAC GPEN / GIAC GWAPT
- ✅ **Saudi / UAE legal entity** with SOC 2 Type II or ISO 27001 of their own
- ✅ **Per-engagement scoping document** delivered before the kick-off (no surprises)
- ✅ **Liability insurance** ≥ AED 5M per engagement
- ✅ **No conflict of interest** with Mojodat / Asset Panda / Maximo / Oracle FA — declared in writing
- ✅ **Big-4-recognisable methodology** (PTES · OWASP Testing Guide · NIST SP 800-115)
- ✅ **Retest included** — no separate scope for verifying the remediation
- ✅ **Right to discuss findings publicly with redactions** for marketing references after 90 days

### 3.2 Soft preferences

- 🟡 **Prior FAM / FA / ERP-integration vertical experience** (vs generic SaaS pen-test)
- 🟡 **AI-specific testing capability** (LLM prompt injection, model-supply-chain) — emerging speciality
- 🟡 **Local Arabic-language reporting option** for the Group COO's review
- 🟡 **Same-time-zone working hours** with the Osolix team (Gulf Standard Time ± 2h)

### 3.3 Deal-breakers

- ⛔ Vendor refuses to sign the standard mutual NDA + IP-protection clause
- ⛔ Vendor sub-contracts to an unidentified third party without written consent
- ⛔ Vendor's lead consultant has < 5 years of pen-test experience
- ⛔ Vendor's reference engagements are all on retail e-commerce (no enterprise B2B SaaS)

### 3.4 Pre-qualified vendor short-list

The CISA Manager maintains a private vendor shortlist (4 firms across UAE / KSA / UK with FAM experience). The list is a separate confidential file — not part of this public engagement pack.

---

## §4 · Engagement timeline

| Week | Phase | Activities | Deliverable |
|---|---|---|---|
| **Week -2** | Vendor selection | RFP shortlist · technical interview · reference-check | Signed master + statement-of-work |
| **Week -1** | Pre-engagement hygiene | Section §5 checklist below; Osolix internal scan with `gitleaks` + license-checker + axe-core; SOX control walkthrough rehearsal | "Ready for engagement" attestation |
| **Week 1** | Recon + pre-test prep | Vendor reads SOX matrix, OpenAPI spec, frontend route map, this engagement pack; Osolix provisions a clean test tenant + 5 named test accounts (one per role tier) | Vendor's written test plan |
| **Week 2** | Active testing | Black-box scan + authenticated tests + targeted manual review per §1.3; daily 30-min standup with the Osolix CISA Manager | Daily findings log |
| **Week 3** | Reporting + remediation kick-off | Vendor delivers draft report → Osolix triages findings → owners assigned; engineering sprints scoped | Final report + remediation tracker |
| **Week 4** | Remediation + retest | Critical + serious findings fixed within 7 days; vendor retests; final clean report | Engagement-close letter |

---

## §5 · Pre-engagement hygiene checklist

The CISA Manager runs this checklist 5 working days before the vendor's kick-off. Any open item is fixed before the test starts.

### 5.1 Code hygiene

- ☐ `gitleaks` CI gate green on the last 30 commits (per `.github/workflows/ci.yml#secrets`)
- ☐ License-compliance CI gate green (per `NOTICE.md`)
- ☐ axe-core a11y CI gate green on the top-15 user flows
- ☐ All EF migrations applied to staging; no pending model changes warning
- ☐ All hosted services running in production (5 dispatchers logged at startup)
- ☐ Last `dotnet build` and `tsc --noEmit` exit 0 in CI

### 5.2 Configuration hygiene

- ☐ `appsettings.Production.json` excluded from source control
- ☐ JWT signing key rotated within the last 12 months
- ☐ DataProtection key ring backed up + restorable
- ☐ `Anthropic:ApiKey` rotated if the engagement might exercise Online AI
- ☐ All ERP credentials in `ErpIntegrationConfig` confirmed encrypted at rest
- ☐ All SSO client secrets in `SsoTenantConfig` confirmed encrypted at rest
- ☐ All SCIM tokens in `ScimToken` confirmed hashed at rest

### 5.3 Audit-trail hygiene

- ☐ `audit.AuditLogs` table accessible to the vendor via a read-only DB user
- ☐ Last 30 days of audit-log entries reviewed for anomalies
- ☐ All 5 hosted services have heartbeat metrics in the logs
- ☐ Login + logout audit events visible in the audit trail per ITGC-A2

### 5.4 Provisioning hygiene

- ☐ Test tenant provisioned with the LifecycleHistoryDemoSeeder run (24 dep runs + 5 transfers + 5 retirements + 30 maintenance)
- ☐ 5 test accounts created — one per role tier (Viewer · AssetManager · TenantAdmin · Auditor · SystemOwner)
- ☐ Each test account's password reset; passwords delivered to the vendor via 1Password share
- ☐ SCIM token minted; raw token delivered to the vendor via the same secure channel
- ☐ One ERP integration config + inbound HMAC token configured for the inbound-webhook test

### 5.5 Documentation hygiene

- ☐ This engagement pack delivered to the vendor as PDF
- ☐ `docs/31-sox-control-matrix.md` delivered to the vendor as PDF
- ☐ `docs/33-accessibility-conformance.md` delivered to the vendor as PDF (informational)
- ☐ `NOTICE.md` delivered (informational, license/IP context)
- ☐ OpenAPI 3.1 spec exported from `/swagger/v1/swagger.json` and pinned to the engagement
- ☐ Architecture diagram (high-level) delivered as PDF

---

## §6 · Remediation tracker template

The CISA Manager maintains a per-engagement remediation tracker in this shape. One row per finding.

| ID | Title | CVSS | Severity | Code path | Owner | Triaged | Patch ETA | Patched | Retested | Verified |
|---|---|---|---|---|---|---|---|---|---|---|
| F-001 | Example: stored XSS in Asset notes field | 7.4 | Serious | `AssetsController.Update` | CTO | 2026-Q3 day 14 | day 17 | day 17 | day 22 | ✅ |
| F-002 | Example: SAML signature method allows SHA-1 | 6.5 | Medium | `SamlController.VerifySignature` | CISA + CTO | day 14 | day 21 | day 21 | day 22 | ✅ |
| F-003 | Example: SCIM PATCH path traversal regression | 8.1 | Serious | `ScimController.PatchUser` | CTO | day 14 | day 16 | day 16 | day 22 | ✅ |
| F-004 | Example: missing CSP header on `/welcome` | 4.3 | Low | `Program.cs` middleware | Automation Mgr | day 14 | day 30 | day 28 | day 30 | ✅ |

### 6.1 Triage SLAs

| Severity | Triage by | Patch by | Retest by |
|---|---|---|---|
| Critical (CVSS ≥ 9.0) | 24 hours | 7 days | 10 days |
| Serious (CVSS 7.0-8.9) | 48 hours | 14 days | 21 days |
| Medium (CVSS 4.0-6.9) | 5 working days | 60 days | 90 days |
| Low (CVSS < 4.0) | 10 working days | next quarter | quarterly |

### 6.2 Escalation path

Any finding past its triage SLA escalates as follows:
1. Engineering owner → CTO (24 hours)
2. CTO → CISA Manager (48 hours)
3. CISA Manager → Group CFO (72 hours)
4. Group CFO → Audit Committee (next regular meeting)

A finding past its patch SLA without an approved exception is automatic stop-ship on the next release.

---

## §7 · Post-engagement governance

### 7.1 Engagement-close artefacts (CISA Manager files)

Filed in the CISA Manager's archive within 30 days of engagement close:
- Final pen-test report (with redactions for client-confidentiality)
- Engagement-close letter signed by Group CFO + CTO + CISA Manager
- Remediation tracker (filled in)
- Vendor reference-letter draft (for future use)
- Lessons-learned memo (1 page) for the next engagement
- Updated `docs/31-sox-control-matrix.md` § 6 if new backlog items emerge
- **Press / marketing** — Strategy Head review · pre-approved 1-paragraph blurb on the engagement (vendor-named or anonymised) for sales enablement use

### 7.2 Cadence

- **Annual** external pen-test (this engagement pack)
- **Quarterly** internal vulnerability scan (Automation Manager runs the SAST + DAST against staging)
- **Continuous** SCA via `gitleaks` + license-checker + dependency CVE feeds in CI

### 7.3 Customer-facing posture

After the first clean engagement, the CISA Manager publishes:
- A 1-page security-statement update on the marketing site referencing the engagement (vendor-anonymised)
- A SOC 2 Type I gap-assessment to feed the next-step compliance roadmap
- An updated security questionnaire response (the standard 200-question enterprise vendor due-diligence)

The engagement-passed status becomes a sales-enablement artefact tracked by the Strategy Head — referenced in
the customer-facing material under sales artifacts 40-44.

---

## §8 · Cost model

| Line | Estimate (AED) | Notes |
|---|---|---|
| Vendor engagement (10 person-days lead consultant + 5 days junior + tools) | 80,000 — 110,000 | Per the rubric in §3 |
| Internal-team time (CISA Mgr 10 days · CTO 3 days · 2 engineering owners 5 days each) | 30,000 (loaded) | Already in run-rate; opportunity cost only |
| Remediation engineering | 20,000 — 50,000 | Depends on findings count + severity |
| Marketing / press support post-pass | 5,000 | Strategy Head's slot |
| **Total budget** | **135,000 — 195,000 AED** | Approved annually in the Q3 OKR planning |

### Cost recovery (commercial)

A clean external pen-test materially shortens enterprise sales cycles. Strategy Head's working number: **5 days off the average enterprise-sales evaluation timeline**. At a list price of AED 0.18/asset/month and a typical 50K-asset Suite SKU prospect, that's **AED 5,400 of accelerated revenue per closed deal**. Engagement breaks even after **30-40 closed enterprise deals** purely on cycle-time acceleration — typically within the first 12 months of the post-pass period.

---

## §9 · Sign-off

By approving this engagement pack the CTO + CISA Manager + Group CFO commit to:
- Funding the engagement at the §8 budget
- Internal capacity to triage + remediate within the §6.1 SLAs
- Not deferring critical or serious findings without explicit Audit Committee approval
- Publishing the engagement-passed status to the customer-facing marketing surface within 30 days of close

**Latest sign-off:** _pending — 2026-05-02_ · Targeted engagement window: 2026-Q3 mid-quarter
