---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure penetration testing

# Configure penetration testing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can configure the sprint duration and estimated effort for penetration testing assessment types. This provides the scheduling functionality for application owners, helping them determine a tentative time frame for their
penetration test assessment requests.

## Before you begin

Role required: Ethical Hacker

## About this task

Configuring the penetration test assessment settings for the ethical hacking team also helps determine the group and point of contact that receives the penetration test assessment request.

Starting with v19.0 of Vulnerability Response, if you are using the Veracode Vulnerability Integration, the penetration assessment tests in the Veracode Vulnerability Integration are manual findings from Veracode. They are not linked to any penetration test assessment requests you configure in Application Vulnerability Response. For more information about penetration test assessments from Veracode, see the [Veracode Vulnerability Integration](https://servicenow-prod.fluidtopics.net/UaJdOAyH3lz8Z703obNHTg "The Vulnerability Response Integration with Veracode application uses data imported from the Veracode product to help you determine the impact and priority of flaws in your code.").

## Procedure

1. Navigate to AllApplication Vulnerability ResponseAdministrationPenetration Testing Configuration.
2. Use the first section to configure the assignment group.
3. On the form, fill in the fields.  
   {#pen-test-config-v16-1__table_zkz_g5k_qqb__entry__2}

   | Field | Description |
   |-|-|
   | Penetration testing team user group | Group to which the penetration test assessment request is assigned. |
   | Default assignee for penetration testing assessment requests | Point of contact for the penetration test assessment request. |
   [Table 1. Penetration Test Configuration form]

   {#pen-test-config-v16-1__table_zkz_g5k_qqb}
4. Select Update.
5. Use the second section to configure sprints.  
   For details, see [Configure sprints for penetration testing](https://servicenow-prod.fluidtopics.net/bLxISzCEOP4LLx41jAcL6g "Configure the sprint duration and capacity for the ethical hacking team so they can manage the sprint capacity for penetration test assessments.").
6. Use the third section to configure assessment types.  
   For details, see [Configure assessment types for penetration testing](https://servicenow-prod.fluidtopics.net/Y27P9ALfF2JCDEzkGVdjgg "Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.").
{#pen-test-config-v16-1__steps_zff_jms_1tb}
* **[Configure sprints for penetration testing](https://servicenow-prod.fluidtopics.net/bLxISzCEOP4LLx41jAcL6g)**   
  Configure the sprint duration and capacity for the ethical hacking team so they can manage the sprint capacity for penetration test assessments.
* **[Configure assessment types for penetration testing](https://servicenow-prod.fluidtopics.net/Y27P9ALfF2JCDEzkGVdjgg)**   
  Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.

*[\>]: and then


