Skip to content

Scope Creep

Definition

The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system or because the client adds targets mid-engagement without a formal scope change. Scope creep creates legal exposure and invalidates the original test design.

Field
Penetration testing and fraud examination
Trigger 1
Tester follows a vulnerability chain into an out-of-scope system
Trigger 2
Client adds targets mid-engagement without formal sign-off
Main risk
Legal exposure and an invalidated test design

Common questions

What should a tester do if a vulnerability chain leads outside the agreed scope?+

Stop before interacting with the out-of-scope system, document what was found, and go back to the client for written authorisation before proceeding. Continuing without that authorisation removes the legal protection the original signed scope provided.

Why does adding targets mid-engagement need a formal change rather than a verbal okay?+

The signed scope of work is what makes testing activity lawful rather than unauthorised access. A verbal add-on leaves no record of what was actually approved, so any dispute later about what was authorised has nothing written to point to.

Related terms

Attestation Letter
A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
Attorney-Client Privilege
A legal protection shielding confidential communications between an attorney and their client from compelled disclosure in litigation. A forensic accountant retained by...
Audit Criteria
The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
Audit Objectives
The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
Audit Plan
The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
Audit Scope
The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
Auditee
The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
Common Vulnerability Scoring System (CVSS)
A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
Concession
An acknowledgment by the expert witness that a particular proposition put by counsel is correct. A partial concession accepts part of a...
Cross-Examination
Questioning of a witness by the opposing party. For an expert, cross-examination probes qualifications, methodology, the basis of opinions, limitations, inconsistencies with...
Daubert Gatekeeping
The judicial function under Daubert v. Merrell Dow Pharmaceuticals (1993) and Federal Rules of Evidence Rule 702, requiring the trial judge to...
Engagement Letter
A written contract between the forensic accountant and the retaining party that defines the scope, deliverables, fee arrangement, confidentiality terms, and the...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.