---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Penetration testing workspace

# Penetration testing workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Penetration testing workspace in Application Vulnerability Response helps customers request for penetration test assessment request and track it using the workflow. It enables application owners to assess the security posture of
their application. It is the manual testing of an application by the ethical hacking team.

## Roles required {#pen_test_workspace_avr__section_uqy_ngb_ddc}

Penetration testing requires the following roles:

sn_vul.app_pen_tester: Represents a pen tester who is responsible to create pen test findings as part of the application penetration testing.

sn_vul.app_pen_test_requester: select record for action: sn_vul.app_pen_test_requester.

## Lifecycle of Penetration Testing {#pen_test_workspace_avr__section_eks_jhb_ddc}

As an application owner, you can request the ethical hacking team for a penetration test assessment of your application. The ethical hacking team acts on this request and creates penetration test findings. These findings are manually
created Application Vulnerable Items (AVIs).

The penetration testing workflow covers the penetration testing life cycle from raising the testing request to resolving the findings of the ethical hacking team.

