官术网_书友最值得收藏!

Executive summary

This section gives a high-level glimpse of the findings and specifies the main aims of the penetration testing. The target audience of this section is the upper management because they care about the security of the organization, more than the technical details. That is why, in an executive summary, it is not recommended you mention the technical specifications of the findings. The executive summary includes the following:

  • A background explains the purpose of the penetration testing and an explanation of some technical terms for the executive, if needed. The upper management, after reading the background, will have a clear idea about the goal and the expected results of the penetration testing.
  • An overall position relating to the effectiveness of the test by highlighting some security issues, such as according to the PTES standard, the business is lacking an effective patch management process.
  • Risk score is a general overview of risk ranking based on a predefined scoring system in the pre-engagement phase. Usually, we use the high/low scoring metrics or a numerical scale.
  • Recommendation summary specifies the required steps and methods to remediate the security issues discussed in the previous point.
  • Strategic roadmap indicates a detailed short- to long-term roadmap to enhance the security of an organization, based on ordered objectives.
主站蜘蛛池模板: 香格里拉县| 阿拉善右旗| 滁州市| 高邑县| 台中县| 宜城市| 龙井市| 姚安县| 祁门县| 师宗县| 唐海县| 陵川县| 平湖市| 堆龙德庆县| 中方县| 临汾市| 田东县| 蚌埠市| 梁山县| 聂拉木县| 许昌市| 金昌市| 循化| 徐州市| 大英县| 噶尔县| 长葛市| 郸城县| 浦东新区| 湘西| 德令哈市| 庆安县| 益阳市| 株洲县| 长葛市| 阿拉善左旗| 吕梁市| 宁强县| 宜良县| 通城县| 新兴县|