Covers authorization boundaries, cybercrime law, privacy duties, evidence handling, responsible disclosure, contracts, and the ethical limits of defensive and offensive testing.