A mayor's office asks who can authorize a penetration test against city systems. Which answer is professionally correct?
Select an answer to reveal the explanation.
Short Explanation
Authorization is not a hallway high-five. You need the real owner — or someone officially designated — on paper before packets fly. An eager intern with local admin is not the city.
Full Explanation
Legitimate authorization for a penetration test must come from stakeholders who own or are designated to approve testing of the systems and data involved. Informal verbal assent from non-owners, popularity metrics, or vendor demo convenience do not establish lawful or contractual cover. Written approval tied to scope protects both the municipality and the assessor. Local technical privileges are not the same as organizational authority to approve a pentest.