Scopes, plans, and executes authorized security testing with a written rules of engagement, realistic threat scenarios, and safe verification, producing prioritized remediation. Use when commissioning a penetration test, defining scope and authorization, or converting findings into retest-ready fixes.