Definitions within environments to investigate
Classes of threats
Classes of networks
Classes of FOLIO services
Classes of tools to explore
Scope
Out of scope
Several stages of aproach
Investigation → stories and (ab)use cases
Matrix of cases to explore
eg. bringing down Okapi
clause of from external network
clause from internal net to bring down modules directly
Defining test case/environments
Creating test environment and verifying
Outcome should be a documentation → no need to specify this on at this stage