Configure assessment types for penetration testing
Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.
Before you begin
Role required: Ethical Hacking
About this task
Each sprint is assigned to a penetration testing request. Based on the estimated effort for the assessment type, the hours are adjusted to reflect the balance hours for the sprint.
Procedure
- Navigate to All > Application Vulnerability Response > Administration > Penetration Testing Configuration.
- Starting with v19.0 of Vulnerability Response, select Configure to display Assessment types, Application size and Estimated effort.
- Optional:
Select an Assessment type record to update the fields as required or create new records.
The Application size values provide you with more options to help estimate test time and effort more accurately. You can edit the hours for these records or select New to create your own combinations.
You can modify Assessment type and Application size on values on existing penetration testing request records so that you can schedule tests to match sprint capacity. For example, if you fill out a test request, you might not see the number of sprints you configured, because some sprints are already taken for testing. If a sprint's estimated effort hours match the combination required for a test's type and size, they are not available for new requests.
You can see the sprints that are assigned to test requests on records on the Penetration Testing Sprints list at All > Application Vulnerability Response > Administration > Penetration Testing Configuration > Configure sprints. See Configure sprints for penetration testing for more information on configuring sprints.
The base values for Assessment type, Application size, and Estimated effort are:
Table 1. Penetration testing assessment type configuration form Assessment type Application size Estimated effort (hrs) Focused Test Small 20 Focused Test Medium 30 Focused Test Large 40 Focused Test Standard 40 Re-Test Small 10 Re-Test Medium 15 Re-Test Large 20 Re-Test Standard 20 Full Penetration Test Small 60 Full Penetration Test Medium 70 Full Penetration Test Large 80 Full Penetration Test Standard 80 - Select Update to save your changes or Submit for a new record.
- Prior to v19.0, select the Configure option for Configure assessment types.
-
Update the values for the assessment types as required.
Base values are:
Table 2. Penetration testing assessment type configuration form Assessment type Estimated effort (hrs) Focused Test 40 Re-Test 20 Full Penetration Test 80 - Save the changes.