← Back to oday.com.au
0day · oday.com.au

Web Application Penetration Test
Scope & Rules of Engagement Template

Type: Application Pen Test Scope Document Version: 2025 Contact: hello@oday.com.au
⚠️ Important: This document must be completed, signed by an authorised representative of the target organisation, and returned to the testing team BEFORE any testing begins. Penetration testing without written authorisation may be illegal.

1. Engagement Details

Client Organisation:

Authorising Contact (Full Name & Title):

Contact Email:

Contact Phone:

Testing Vendor: Oday Cybersecurity — hello@oday.com.au — 0420 277 414

Test Type:

2. Testing Window

FieldValue
Planned Start Date
Planned End Date
Permitted Testing Hours
Emergency Contact During Testing

3. In-Scope Targets

List all URLs, IP addresses, and systems authorised for testing.

Target URL / IPDescriptionEnvironmentStatus
In Scope
In Scope
In Scope
In Scope

4. Out-of-Scope Targets

List any systems, URLs, or components that must NOT be tested.

TargetReason for Exclusion

5. Test Credentials

Account TypeUsernameNotes
Standard User
Admin User
Other Role

Passwords will be shared via encrypted channel (1Password or Signal) — not email.

6. Rules of Engagement

Testing team agrees to:

DoS/Load Testing Authorised?

Social Engineering / Phishing Authorised?

Physical Security Testing Authorised?

7. Communication Protocol

In the event of a discovered critical issue during testing, the testing team will contact:

PriorityNamePhoneEmail
Primary
Secondary

8. Authorisation & Signatures

By signing below, the client confirms they are authorised to permit this testing and accept the rules of engagement above.

Client Authorised Signature
Oday Testing Team Lead
Name: ___________________
Date: ___________________