ClearPenTest

Testing

Asset

Also called: in-scope asset, external asset, asset count, scope unit

In penetration testing scope, an asset is one distinct thing being tested: a repository, or a hostname or IP serving a distinct application or API. Pages and routes within a single application are not separate assets.

The definition matters commercially, because most fixed-price testing is sold against an asset ceiling and vendors count differently. A firm that counts every subdomain, including redirects, reaches a higher tier than one that counts applications, for identical work.

At ClearPenTest, repositories and hostnames count equally. A white box assessment's effort scales with the code as much as with the running surface, so pricing on hostnames alone would charge a team with forty repositories and one domain the same as a team with one of each.

Not counted separately: routes inside an application, subdomains that only redirect to a counted host, a staging environment mirroring a counted production host, and forks of a counted repository.

START WITH A CLEAR SCOPE

Testing, with the report an auditor can actually use

Scope an assessment