Configure assessment types for penetration testing

  • Release version: Zurich
  • Updated July 31, 2025
  • 1 minute to read
  • Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.

    Before you begin

    Role required: Ethical Hacking

    About this task

    Each sprint is assigned to a penetration testing request. Based on the estimated effort for the assessment type, the hours are adjusted to reflect the balance hours for the sprint.

    Procedure

    1. Navigate to All > Application Vulnerability Response > Administration > Penetration Testing Configuration.
    2. Starting with v19.0 of Vulnerability Response, select Configure to display Assessment types, Application size and Estimated effort.
    3. Optional: Select an Assessment type record to update the fields as required or create new records.

      The Application size values provide you with more options to help estimate test time and effort more accurately. You can edit the hours for these records or select New to create your own combinations.

      You can modify Assessment type and Application size on values on existing penetration testing request records so that you can schedule tests to match sprint capacity. For example, if you fill out a test request, you might not see the number of sprints you configured, because some sprints are already taken for testing. If a sprint's estimated effort hours match the combination required for a test's type and size, they are not available for new requests.

      You can see the sprints that are assigned to test requests on records on the Penetration Testing Sprints list at All > Application Vulnerability Response > Administration > Penetration Testing Configuration > Configure sprints. See Configure sprints for penetration testing for more information on configuring sprints.

      The base values for Assessment type, Application size, and Estimated effort are:

      Table 1. Penetration testing assessment type configuration form
      Assessment type Application size Estimated effort (hrs)
      Focused Test Small 20
      Focused Test Medium 30
      Focused Test Large 40
      Focused Test Standard 40
      Re-Test Small 10
      Re-Test Medium 15
      Re-Test Large 20
      Re-Test Standard 20
      Full Penetration Test Small 60
      Full Penetration Test Medium 70
      Full Penetration Test Large 80
      Full Penetration Test Standard 80
    4. Select Update to save your changes or Submit for a new record.
    5. Prior to v19.0, select the Configure option for Configure assessment types.
    6. Update the values for the assessment types as required.
      Base values are:
      Table 2. Penetration testing assessment type configuration form
      Assessment type Estimated effort (hrs)
      Focused Test 40
      Re-Test 20
      Full Penetration Test 80
    7. Save the changes.