官术网_书友最值得收藏!

Executive summary

This section gives a high-level glimpse of the findings and specifies the main aims of the penetration testing. The target audience of this section is the upper management because they care about the security of the organization, more than the technical details. That is why, in an executive summary, it is not recommended you mention the technical specifications of the findings. The executive summary includes the following:

  • A background explains the purpose of the penetration testing and an explanation of some technical terms for the executive, if needed. The upper management, after reading the background, will have a clear idea about the goal and the expected results of the penetration testing.
  • An overall position relating to the effectiveness of the test by highlighting some security issues, such as according to the PTES standard, the business is lacking an effective patch management process.
  • Risk score is a general overview of risk ranking based on a predefined scoring system in the pre-engagement phase. Usually, we use the high/low scoring metrics or a numerical scale.
  • Recommendation summary specifies the required steps and methods to remediate the security issues discussed in the previous point.
  • Strategic roadmap indicates a detailed short- to long-term roadmap to enhance the security of an organization, based on ordered objectives.
主站蜘蛛池模板: 泰和县| 集安市| 互助| 乡城县| 平舆县| 宜阳县| 楚雄市| 乳源| 万全县| 方山县| 乌兰浩特市| 林口县| 盘锦市| 开平市| 慈溪市| 克山县| 德令哈市| 芮城县| 酒泉市| 怀远县| 清苑县| 布拖县| 林甸县| 托里县| 嘉荫县| 盐亭县| 本溪市| 贵州省| 浙江省| 温宿县| 扎兰屯市| 宜宾县| 定西市| 盘锦市| 且末县| 长治县| 界首市| 蕉岭县| 南华县| 同德县| 盐山县|