If you are unsure how to count something, an estimate is fine. We will confirm details before testing begins.
Tenant / Domains. Your Microsoft Entra ID (formerly Azure Active Directory) tenant and the domains associated with it.
Subscriptions. A billing and access boundary in Azure that contains one or more resource groups.
Resource Groups. A container that holds related resources for an Azure solution.
Resources. An individual item within a resource group, such as a VM, database, or storage account.
Enterprise Applications. An application's identity within your directory (Entra ID).
Storage Accounts. An Azure storage account holds your Azure Storage data objects: blobs, files, queues, and tables.
Virtual Network (VNet). Azure's private network that connects and isolates your Azure resources (the Azure equivalent of a VPC).
Cloud — Amazon Web Services (AWS)
AWS Accounts. If the engagement involves multiple AWS accounts (not regions), include the number of accounts in scope.
AWS Console Access. The number of users or roles with access to the AWS console, regardless of access level.
EC2 (Elastic Compute Cloud). Virtual servers running in AWS. The total count helps determine the effort involved.
ECS (Elastic Container Service). AWS's container orchestration service. The number of containers or tasks in use helps determine the effort involved.
EKS (Elastic Kubernetes Service). AWS's managed Kubernetes service. Further questions about the architecture may follow.
S3 (Simple Storage Service). Object storage. Further questions may follow about which buckets are public and which are private.
Lambda. AWS's serverless compute service, which runs code without provisioning servers.
VPC (Virtual Private Cloud). A logically isolated network in AWS where your resources run. The number of VPCs helps determine network scope.
Cloud — Google Cloud (GCP)
Organizations. The top-level container for your Google Cloud resources, usually tied to your company domain.
Projects. The GCP projects involved in the engagement. Resources, billing, and permissions are organized by project.
Compute Engine. Virtual machine instances running in GCP.
GKE (Google Kubernetes Engine). Google's managed Kubernetes service. Count the clusters and approximate number of pods.
Cloud Storage Buckets. Buckets used for object storage in GCP.
Cloud Run functions / services. Serverless functions and containerized applications running on Cloud Run.
VPC (Virtual Private Cloud). Google Cloud's networking layer for Compute Engine VMs, GKE clusters, and serverless workloads.
Cloud — All Providers
Regions. The number of geographic regions where you run resources that are in scope.
Kubernetes Clusters. A set of nodes that run containerized workloads. Each cluster runs one or more pods.
Kubernetes Node Pools. A group of nodes within a cluster that share the same configuration (CPU, memory, networking, OS, maximum pods, etc.).
Internal vs. External Kubernetes Testing. Internal testing means the testing team is given a kubeconfig or access to a pod, and hardening is assessed from inside the cluster. External testing looks at the cluster from an outside perspective.
Applications
API Endpoints. The specific paths on the server that handle requests and responses. The total number helps determine the size of the application.
Dynamic Pages. Pages generated in real time from a database, with content that changes based on user input. The count helps determine the testing effort.
User Roles. The number of distinct user roles in the application. If roles are dynamic, state the number you'd like tested.
Single Page App (SPA). An application that updates a single HTML page in response to user actions, typically built with React, Angular, or Vue.
Authentication. Whether the application requires users to log in, plus any details you can share about how.
Serverless. Whether the application runs on serverless infrastructure, such as AWS Lambda or Azure Functions.
On-Prem IT
External IPs. Internet-facing IP addresses that are currently live.
Physical Servers. Bare-metal servers, which may host several VMs.
VMs. The number of virtual machines across the environment.
Endpoints. End-user devices and workstations, primarily domain-joined Windows PCs and Macs.
Network Components. Primarily switches, routers, and firewalls. Access points and phones can be noted, but count one per device type.
Active Directory Domain. A collection of objects, possibly spanning multiple domain controllers, counts as one domain. For example, acme.local is one domain; a separate acme-corp.local with no trust relationship would be a second.
PCI Segments. The number of PCI network segments (subnets) in scope.
Cardholder Data Environment (CDE). The part of a network that stores, processes, or transmits cardholder data or sensitive authentication data.
Operational Technology (OT)
PLCs / Critical Infrastructure (High Risk). Systems with high potential for harm if compromised, such as those running power generation, water treatment, or transportation networks.
Misc. OT Devices (Medium Risk). Systems such as HVAC controls, smart meters, test-environment PLCs, and backup controllers.
Misc. OT Devices (Low Risk). Non-essential monitoring devices, lab equipment, and other OT that doesn't directly affect critical processes.
OT Environments. A distinct operational site or segmented control network (e.g., a plant, facility, or production line) with its own OT assets.