Customer must be authorised for every system it scans or tests
Catalog row in Vendor License Rules · Cited
- Kind
- Use rights
- Statement
- MSSA §2.2 and §9.9: the customer warrants that it has appropriate authorisations for the networks, systems, IP addresses, assets and hardware it deploys the Offerings on or targets, scans, monitors or tests, and must comply with laws governing network scanners and vulnerability assessment software. Scanning or testing third-party assets without authorisation is outside the licence and triggers the customer indemnity in §6.2.
- Applies when
- Scanning cloud providers, partners or subsidiaries not owned by the customer.
- Applies to
- InsightVM, Nexpose, Metasploit, InsightAppSec, Surface Command.
- Related metrics