Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a penetration test assessment request from existing requests (v19.0)

Starting with v19.0, you create penetration test assessment requests directly from the list of existing requests. You can also copy existing requests in the Closed state on this list to create requests.

Before you begin

Role required: Application Owner

About this task

Starting with v19.0 of Vulnerability Response, if you are using the Veracode Vulnerability Integration, the penetration assessment tests in the Veracode Vulnerability Integration are manual findings from Veracode. They are not linked to any penetration test assessment requests you configure in Application Vulnerability Response. For more information about penetration test assessments from Veracode, see the Veracode Vulnerability Integration.

Procedure

  1. Navigate to All > Penetration Test Assessment Requests > All.

  2. Alternatively, you can create a request by replicating closed requests.

    All the values from the original request are preserved in the new form. Active application vulnerable items (AVIs) are automatically copied to the new request. Select Copy And Create Request from records in the Closed state.

  3. Select New and fill out the fields.

FieldDescription
NumberUnique identifier generated for the penetration test assessment request.
StateSelect a value based on the status of the request.
Requested byPerson requesting the assessment of the application.
Assignment groupGroup selected to work on the penetration test findings. Can be manually added or edited by an App-Sec Manager.To configure groups, see Configure penetration testing.
ApplicationSelect an application using the search option.
Assigned toIndividual from the selected assignment group that works on the penetration test findings. Can be manually added or edited by an App-Sec Manager.
Application typeSelect an option from:- Web service (known as API prior to v16.1) - Web Application - Thick Client - Mobile (If you select Mobile, the Mobile tab is displayed at the bottom of the form with additional fields)
SprintDisplays the sprints with bandwidth available to accommodate the assessment request based on the selected Assessment type field.See Configure sprints for penetration testing and Configure assessment types for penetration testing for more information about modifying sprint capacity and testing scope.
v19.0: Application sizeSelect the size of the application you want to test.- Small - Medium - Large - Standard \(select this option if you are not sure of the size\) See more Configure penetration testing more information about modifying sprint capacity and testing scope with application size and sprint capacity.
CreatedDate and time the request was created.
Assessment typeSelect the type of assessment from:- Full penetration Test - Focused Test - Re-test For more details about testing combinations and testing scope, see Configure assessment types for penetration testing.
UpdatedDate and time the request was last updated.
Demo dateDate when this application can be demonstrated.
Product deployment planned onPlanned date to deploy this application in production.
Application version/release planned for deploymentVersion of the application planned for production deployment.
v19.0: Application owned by third-party vendor or a joint venture tabIf you select Yes for this field, the Vendor/ Joint Venture Information tab is displayed. Fill in the additional fields.
Clause exists that enables us to perform pen testing?The term 'Clause' might refer to standards for testing that include any agreements that exist between two or more parties you want to add. If you select Yes, add the clause.
The clause citing the permission to perform pen testing 
Full legal name and address of the vendor 
Intrusion detection system 
Technical contact from vendor 
Has the logged information been reviewed form malicious activity? 
Application hosted by another third-party vendor? 
Contact from vendor who will be signing off on the pen test 
Application Details tab
Purpose of applicationDescription of the application’s functionality.
Technology stack detailsComplete technology stack from front end to back-end, databases, and other key technologies.
Is third-party application?Confirms if this application is owned by a third-party vendor.
List types of sensitive data accessible from applicationTypes of sensitive data accessible from the application. For example, PII data, PHI data, and financial data such as credit card numbers.
Authentication typeSpecifies if this application uses LDAP authentication, its own native authentication, or other forms of authentication.
Is application in scope for any compliance program?Specifies if this application impacts any compliance programs such as PCI.
Application team contactsMembers of the application team to be contacted by the ethical hacking team for any questions.
List of compliance programs 
Related third-party interfaces or applications 
IP address 
Approximate number of users in production? 
Automated script exists? 
Production version of this app is external-facing? 
v 19.0: Business Impact
Financial damageSelect one from the list.
Non-complianceSelect one from the list.
Reputation damageSelect one from the list.
Privacy violationSelect one from the list.
Testing details tab
URLs to testURLs that must be included in penetration testing.
URLs to excludeURLs that must be excluded from penetration testing.
Was this application tested previously?Specifies if this application has already been penetration tested.
Reason for retestReason for asking for a penetration test reassessment if the application was tested earlier.
When was the application tested?Time frame when the application was penetration tested.
Test account detailsDetails of the test account that can be used by ethical hacking team for penetration testing.
Application rolesRoles supported by the application for its users.
Most used rolesMost commonly used roles in the application.
Additional Comments tab 
Work notes 
  1. Select Save to save your edits or Submit to initiate the request.