Scope of work
Living template · v1.1.0 · 2026-07-12. Each engagement instantiates this template with concrete values; the instantiated SOW is attached to the MSA.
1. Assets in scope
- Domains and subdomains (verified via DNS TXT handshake).
- Public IPv4 / IPv6 addresses and CIDR ranges owned by the Customer.
- Container images pushed to the Customer’s registry.
- Web applications reachable at listed URLs.
Live inventory: /assets.
2. Scan types & cadence
| Engine | Purpose | Default cadence |
|---|---|---|
| Edge | External surface, TLS, headers | Daily |
| Nmap | Port & service discovery | Weekly (chunked) |
| Nuclei | CVE / misconfiguration templates | Daily (chunked by severity) |
| ZAP baseline | Passive web scan | Weekly |
| Trivy | Container / image CVEs | On every image push |
3. Deliverables
- Live dashboard access (/dashboard) with posture score and findings.
- Per-finding remediation guidance with severity, CVSS, and evidence.
- Monthly executive summary PDF emailed to the security contact.
- Compliance mappings (SOC 2, GDPR, ISO 27001, NIST CSF, CIS v8) at /compliance.
- Raw scan reports downloadable from /scans.
4. Service levels
- Critical finding notification: within 24 hours of confirmation.
- High finding notification: within 72 hours.
- Platform availability: 99.5% monthly, excluding scheduled maintenance.
- Support response: next business day (US Eastern).
5. Acceptance criteria
- At least one verified asset with a successful scan in the last 30 days.
- MFA enrolled on all user accounts.
- Findings dashboard populated and reachable by the Customer’s designated contact.
- Monthly executive summary delivered on time.
6. Assumptions & exclusions
- Customer maintains DNS access to keep verification records live.
- Customer will not block NSO scan source ranges in its WAF.
- Fragile / OT / medical / production-DB assets are excluded unless separately contracted.
- Remediation execution is Customer’s responsibility; NSO provides guidance only.
7. Change control (living document)
Changes to scope, cadence, or deliverables are versioned in the changelog and reflected on this page in the same release. Material changes to a specific engagement require an emailed acknowledgement from the Customer’s security contact.