Testing performed using covert methods and without the knowledge of the organization’s IT staff, but with full knowledge and permission of upper management.
Source(s):
NIST SP 800-115