Testing
Asset
Also called: in-scope asset, external asset, asset count, scope unit
In penetration testing scope, an asset is one distinct thing being tested: a repository, or a hostname or IP serving a distinct application or API. Pages and routes within a single application are not separate assets.
The definition matters commercially, because most fixed-price testing is sold against an asset ceiling and vendors count differently. A firm that counts every subdomain, including redirects, reaches a higher tier than one that counts applications, for identical work.
At ClearPenTest, repositories and hostnames count equally. A white box assessment's effort scales with the code as much as with the running surface, so pricing on hostnames alone would charge a team with forty repositories and one domain the same as a team with one of each.
Not counted separately: routes inside an application, subdomains that only redirect to a counted host, a staging environment mirroring a counted production host, and forks of a counted repository.