Defining Engagement Scope
The Engagement Scope defines the exact set of assets and services you wish to include in a security assessment when initiating a new engagement through the Strobes PTaaS (Pentesting-as-a-Service) platform.
Think of the scope as your “order summary.” it details what needs to be tested, how it needs to be tested, and which assets are involved. Clearly defining your scope ensures accurate planning, resource allocation, and efficient delivery of the assessment.
What Does the Scope Include?
Your scope includes:
- Type of assessment(s) you want to run (e.g., Web App Pentest, API Security Test, Network VAPT)
- Number and type of assets you want assessed (e.g., domains, IPs, cloud environments)
- Specific assets selected from your asset inventory in Strobes
How to Define the Scope (Step-by-Step)
Let’s say you want to get 10 web applications and 500 IP addresses tested.
Here’s how to define the scope during engagement creation:
- Log in to your Strobes PTaaS dashboard.
- Go to "Engagements" in the left navigation panel and click “Create New Engagement”.
- In the Engagement Details section:
- Provide a name and description for your engagement.
- Select the appropriate services:
- Web Application Penetration Test
- Network Vulnerability Assessment & Penetration Testing (VAPT)
- Proceed to the Scope Definition section:
- From your organization’s asset inventory, select the assets that need to be tested.
- For Web App PT: Select the 10 web applications
- For Network VAPT: Select the 500 IPs
- From your organization’s asset inventory, select the assets that need to be tested.
- Review and confirm the selected assets and services — this forms your final engagement scope.
- Click “Submit” to send the engagement to the Strobes pentesting team.
Why Scope Matters
- Precision – Ensures only approved and verified assets are tested
- Transparency – Clarifies what will and will not be covered in the engagement
- Efficiency – Helps our pentesters prepare tools, time estimates, and deliverables
- Reporting Accuracy – Aligns your final report exactly with your defined scope
Best Practices
- Always review your asset inventory before initiating an engagement.
- Avoid scope creep — only include assets you are authorized to test.
- If unsure, start with a smaller scope and scale up with additional engagements later.
- For complex environments (e.g., hybrid cloud, segmented networks), consider breaking them into multiple engagements.