0% found this document useful (0 votes)
31 views4 pages

Penetration Testing Scoping Form

This document is a scoping questionnaire for penetration testing services, aimed at gathering information about an organization's technology infrastructure and testing needs. It includes sections for external and internal penetration tests, wireless network tests, web application tests, and mobile application tests, along with explanations for each type of testing. The information provided is confidential and is used to plan and recommend security enhancements based on the findings.

Uploaded by

Himawan Reinaldy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
31 views4 pages

Penetration Testing Scoping Form

This document is a scoping questionnaire for penetration testing services, aimed at gathering information about an organization's technology infrastructure and testing needs. It includes sections for external and internal penetration tests, wireless network tests, web application tests, and mobile application tests, along with explanations for each type of testing. The information provided is confidential and is used to plan and recommend security enhancements based on the findings.

Uploaded by

Himawan Reinaldy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

No.

Form : F01B-SEC
PENETRATION TESTING
SCOPING QUESTIONNAIRE Rev : 1.0

Tanggal : 13/3/2024

The intent of this form is to gather initial information about your technology infrastructure
and testing intent so that we can properly plan a penetration test / security exercise. Our
services will safely evaluate the security of your resources against attacks from a malicious
source. Based on our findings, we recommend methods to bolster and prevent such attacks
from occurring.

All information provided in this form is strictly confidential. Send forms to hi@[Link]

1. WEBSITE FOR YOUR ORGANIZATION

2. DO YOU WANT AN EXTERNAL PENTEST ?

How many estimated live internet-exposed resources are in-scope, such as servers, VPN
gateways, websites, and firewalls?

Explanation: Our team of ethical hackers will simulate an attack from an external perspective, assessing the
security of your internet-exposed resources and recommending methods to further harden your network.

3. DO YOU WANT AN INTERNAL PENTEST ?

How many estimated internal hosts are in-scope, such as computers and servers?

Explanation: Via a secure remote connection device, our team of ethical hackers will simulate an attack from
the perspective of an attacker who has gained access to your internal network, such as via a phishing attack or a
malicious insider, assessing your security and recommending methods to further harden your network.

[Link] - YOUR IT SECURITY PARTNERS 1


No. Form : F01B-SEC
PENETRATION TESTING
SCOPING QUESTIONNAIRE Rev : 1.0

Tanggal : 13/3/2024

4. DO YOU WANT A WIRELESS NETWORK PENTEST ?

How many wireless networks are in-scope for testing?

If not, how many locations need testing?

Explanation: Via a secure remote connection device, our team of ethical hackers will simulate an attack from
the perspective of an attacker who has gained access to your internal network, such as via a phishing attack or a
malicious insider, assessing your security and recommending methods to further harden your network.

5. DO YOU WANT A WEB APPLICATION PENTEST ?

How many web applications are in-scope for testing?

Please list the URL for each in-scope web application:

How many sets of roles are to be tested for each application?

How many estimated dynamic pages does each application contain?

Are there calls to your own API(s) made by the application(s) that are in-
scope for testing?

If so, how many estimated API calls are in-scope for each application?

Explanation: Our team of ethical hackers will assess the security of your web application from the perspective
of an external attacker. In addition, with provided credentials, we will assess the security of the entire
application from the perspective of an authenticated user. We will review various attack threats, such as the
OWASP Top Ten Security Vulnerabilities, and recommend methods to further harden your application. If your
application architecture utilizes your own APIs that are called by the application, please indicate the total
number of calls so we can assess each for security issues.

[Link] - YOUR IT SECURITY PARTNERS 2


No. Form : F01B-SEC
PENETRATION TESTING
SCOPING QUESTIONNAIRE Rev : 1.0

Tanggal : 13/3/2024

6. DO YOU WANT A MOBILE APPLICATION PENTEST ?

How many mobile applications are in-scope for testing?

Version of mobile application ?

Android IOS

Type of mobile application ?

Hybrid Native

Are there calls to your own API(s) made by the application(s) that are in- scope for testing?

If so, how many estimated API calls are in-scope for each application?

Explanation: Our team of ethical hackers will assess the security of your web application from the perspective
of an external attacker. In addition, with provided credentials, we will assess the security of the entire
application from the perspective of an authenticated user. We will review various attack threats, such as the
OWASP Top Ten Security Vulnerabilities, and recommend methods to further harden your application. If your
application architecture utilizes your own APIs that are called by the application, please indicate the total
number of calls so we can assess each for security issues.

[Link] - YOUR IT SECURITY PARTNERS 3


No. Form : F01B-SEC
PENETRATION TESTING
SCOPING QUESTIONNAIRE Rev : 1.0

Tanggal : 13/3/2024

7. ARE THERE ANY ADDITIONAL NOTES, CONCERNS, OR PARAMETERS


THAT NEED TO BE CONSIDERED ?

[Link] - YOUR IT SECURITY PARTNERS 4

You might also like