Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Laws are applied to enemies, but only interpreted as regards friends.
—Giovanni Giolitti, 1842–1928
Penetration testing, whether physical or electronic, carries with it a certain degree of inherent legal risk. It's important to understand the relevant legislation and how it affects penetration testers. It is sometimes very easy for a perfectly legal test to inadvertently cross the line into questionable legal territory. Usually this happens when the tester exceeds the scope of the test or the rules of engagement, but sometimes you can be engaged to do work (with both sides acting in good faith) that is intrinsically illegal. Understanding the law ensures that you don't put yourself (or your clients) in a legally vulnerable position. The legislation most relevant to the penetration tester may be found in the following acts of parliament: