Scope of testing
List specific hostnames, IP ranges, and services allowed for testing; exclude any production or student-information systems to limit collateral risk.
A properly completed Education Metasploit Form establishes clear authorization, documents consent from system owners, reduces the chance of accidental disruption, and creates an evidentiary trail for accountability and incident response while aligning classroom activity with institutional policies and applicable law.
Each signer should have role-appropriate authority and training; signatures show agreement to safeguards and reporting duties.
List specific hostnames, IP ranges, and services allowed for testing; exclude any production or student-information systems to limit collateral risk.
Specify permitted Metasploit modules, payload restrictions, and disallowed techniques (e.g., destructive exploits or social engineering) to protect infrastructure and personal data.
Identify required approvers (instructor, IT owner, security officer) with signature or eSignature fields and required turnaround times for approvals.
Describe data collection limits, retention rules, and any protections needed for education records (FERPA) or health data (HIPAA) when applicable.
Require immediate reporting of test‑caused outages or discovered vulnerabilities and define remediation ownership and timelines.
Document required training, supervision levels for students, and escalation paths for unexpected findings or safety issues.
| Field | Configuration |
|---|---|
| Authentication | Email + institutional SSO preferred |
| Conditional fields | Show remediation owner only if vulnerabilities found |
| Routing | Sequential: requester → instructor → IT/security |
| Audit trail | Capture timestamps, IP, and signer email |
Storing signed copies in a secure institutional repository with retained metadata preserves attribution and supports incident review.
| Criteria | Education Metasploit Form | Generic Vulnerability Report |
|---|---|---|
| Required approvals | yes, multi-party | often single reporter |
| Notarization | ||
| FERPA risk noted | yes when student data | usually no |
| Technical scope listed | detailed ip/hosts | summary findings |
Submit at least 5 business days before planned test
Allow 2–3 business days for multi-party signoff
Limit tests to specified hours and dates
Report findings within 48 hours of discovery
Retention begins on final signed date
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |