Vulnerability Assessment
Definition
A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity ratings but does not typically involve active exploitation.
- Output
- List of findings with severity ratings
- Involves exploitation
- Typically no
- Scope
- Systems, software, and infrastructure
- Common severity scale
- CVSS scoring is widely used
Common questions
How does a vulnerability assessment differ from a penetration test?+
A vulnerability assessment catalogs and rates weaknesses, largely through scanning and configuration review, while a penetration test goes further by actively attempting to exploit a subset of those weaknesses to demonstrate real-world impact and chain findings into an attack path.
Why is a vulnerability assessment used as audit evidence?+
Auditors treat a dated, scoped assessment report as documentary proof that an organization identified its weaknesses at a point in time, which supports claims of due diligence and can be checked against later remediation records to see if findings were actually closed.
Related terms
- Approved Scanning Vendor (ASV)
- An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates...
- Audit Evidence
- Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it),...
- CVSS (Common Vulnerability Scoring System)
- An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10...
- Remediation Prioritisation
- The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating...
- Risk Acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...