EN - FR - DE - ES - IT - PT -

LexiconDream

🔎 Vulnerability Assessment

A systematic review of a system to identify security flaws.

Vulnerability Assessment

A vulnerability assessment scans systems for known weaknesses. It is not a penetration test. A pen test tries to exploit flaws. A vulnerability assessment identifies and lists them. The output is a report with findings ranked by severity. The organization decides what to fix and when. Assessments are faster and cheaper than pen tests, which is why they run more often. Quarterly scans are common. Continuous scanning is becoming standard.

The tools vary. Network scanners like Nessus and OpenVAS probe hosts for open ports, outdated software, and missing patches. Web application scanners like Burp Suite and OWASP ZAP crawl sites for injection flaws, broken authentication, and misconfigurations. Cloud security posture tools check configurations against benchmarks. Each tool has blind spots. Scanners produce false positives and miss logic flaws that require human analysis. A vulnerability assessment is a starting point. It tells you where to look. It does not tell you what an attacker would actually do. Combining assessment with penetration testing gives a fuller picture. The scan finds the holes. The pen test proves which ones matter.

Vulnerability assessment steps

  1. Define scope and inventory assets
  2. Run automated scans
  3. Validate findings and remove false positives
  4. Prioritize by severity and context
  5. Remediate and rescan to confirm

A scan that runs but never leads to fixes is a compliance exercise. The value is in the remediation.

Comments

No comments yet. Be the first to share a thought.

Leave a comment