Remediation Verification Test
Definition
A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that the specific findings are resolved and that the fix has not introduced new weaknesses. Distinct from a full penetration test and typically lower cost.
- Domain
- Penetration testing
- Purpose
- Confirm fixes hold
- Scope
- Prior findings only
- Cost vs full test
- Typically lower
Common questions
How does a remediation verification test differ from a full re-test?+
It targets only the specific vulnerabilities reported in the original assessment, rather than repeating the entire scope, which keeps it faster and cheaper.
Can a fix introduce a new problem that the verification test would catch?+
Yes, the re-test also checks that the applied fix itself has not created a new weakness at the same point.
Related terms
- Attestation Letter
- A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
- Common Vulnerability Scoring System (CVSS)
- A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
- Red Team Exercise
- A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical)...
- Rules of Engagement (RoE)
- The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...