---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure assessment types for penetration testing

# Configure assessment types for penetration testing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.

## Before you begin

Role required: Ethical Hacking

## About this task

Each sprint is assigned to a penetration testing request. Based on the estimated effort for the assessment type, the hours are adjusted to reflect the balance hours for the sprint.

## Procedure

1. Navigate to AllApplication Vulnerability ResponseAdministrationPenetration Testing Configuration.
2. Starting with v19.0 of Vulnerability Response, select Configure to display Assessment types, Application size and Estimated effort.
3. **Optional:** Select an Assessment type record to update the fields as required or create new records.  
   The Application size values provide you with more options to help estimate test time and effort more accurately. You can edit the hours for these records or select New to create your own
   combinations.

   You can modify Assessment type and Application size on values on existing penetration testing request records so that you can schedule tests to match sprint capacity. For example, if you fill out a test request, you might
   not see the number of sprints you configured, because some sprints are already taken for testing. If a sprint's estimated effort hours match the combination required for a test's type and size, they are not available for
   new requests.

   You can see the sprints that are assigned to test requests on records on the Penetration Testing Sprints list at AllApplication Vulnerability ResponseAdministrationPenetration Testing ConfigurationConfigure sprints. See [Configure sprints for penetration testing](https://servicenow-prod.fluidtopics.net/bLxISzCEOP4LLx41jAcL6g "Configure the sprint duration and capacity for the ethical hacking team so they can manage the sprint capacity for penetration test assessments.") for more information on configuring sprints.

   The base values for Assessment type, Application size, and Estimated effort are:
   {#pen-test-config-assessment-types__table_vmy_1sb_2yb__entry__3}

   | Assessment type | Application size | Estimated effort (hrs) |
   |-|-|-|
   | Focused Test | Small | 20 |
   | Focused Test | Medium | 30 |
   | Focused Test | Large | 40 |
   | Focused Test | Standard | 40 |
   | Re-Test | Small | 10 |
   | Re-Test | Medium | 15 |
   | Re-Test | Large | 20 |
   | Re-Test | Standard | 20 |
   | Full Penetration Test | Small | 60 |
   | Full Penetration Test | Medium | 70 |
   | Full Penetration Test | Large | 80 |
   | Full Penetration Test | Standard | 80 |
   [Table 1. Penetration testing assessment type configuration form]

   {#pen-test-config-assessment-types__table_vmy_1sb_2yb}
4. Select Update to save your changes or Submit for a new record.
5. Prior to v19.0, select the Configure option for Configure assessment types.
6. Update the values for the assessment types as required.  
   Base values are:{#pen-test-config-assessment-types__table_zkz_g5k_qqb__entry__2}

   | Assessment type | Estimated effort (hrs) |
   |-|-|
   | Focused Test | 40 |
   | Re-Test | 20 |
   | Full Penetration Test | 80 |
   [Table 2. Penetration testing assessment type configuration form]

   {#pen-test-config-assessment-types__table_zkz_g5k_qqb}
7. Save the changes.
{#pen-test-config-assessment-types__steps_u3w_mns_1tb}

*[\>]: and then


