WebApp Scoping
Black, White or Grey Box
Environment
List of Hosts and IP Addresses
Operating Systems
Which are the business security concerns regarding the application in scope
What is the main functionality of this application
How is authentication performed? (SSO, Self-Registration etc.)
Does the login function employ any other type of credentials such as physical tokens or client-side certificates
How many type of user roles exist, Credentials must be provided if required for testing
Is there any vertical segregation of access within the application
Is there any horizontal segregation of access within the application
Which server side technologies does the application use? (C#, Java, ASP.NET, IIS, Apache, WAF etc.)
Are there any API's
Are there any Web Services If yes what kind (SOAP, REST etc.)
Does the application interact with a database
Who will act as a secondary contact
Are there any constraints
Documents - HLD etc
3rd Party Acceptance
Last updated