- Advanced Infrastructure Penetration Testing
- Chiheb Chebbi
- 219字
- 2021-06-24 19:12:57
Executive summary
This section gives a high-level glimpse of the findings and specifies the main aims of the penetration testing. The target audience of this section is the upper management because they care about the security of the organization, more than the technical details. That is why, in an executive summary, it is not recommended you mention the technical specifications of the findings. The executive summary includes the following:
- A background explains the purpose of the penetration testing and an explanation of some technical terms for the executive, if needed. The upper management, after reading the background, will have a clear idea about the goal and the expected results of the penetration testing.
- An overall position relating to the effectiveness of the test by highlighting some security issues, such as according to the PTES standard, the business is lacking an effective patch management process.
- Risk score is a general overview of risk ranking based on a predefined scoring system in the pre-engagement phase. Usually, we use the high/low scoring metrics or a numerical scale.
- Recommendation summary specifies the required steps and methods to remediate the security issues discussed in the previous point.
- Strategic roadmap indicates a detailed short- to long-term roadmap to enhance the security of an organization, based on ordered objectives.
推薦閱讀
- Learning OpenDaylight
- Windows Server 2019 Cookbook
- 從零開始寫Linux內核:一書學透核心原理與實現
- Linux內核完全注釋(20周年版·第2版)
- 玩到極致 iPhone 4S完全攻略
- Windows Server 2012 Hyper-V Cookbook
- 高性能Linux服務器構建實戰:運維監控、性能調優與集群應用
- Implementing Azure DevOps Solutions
- Instant Optimizing Embedded Systems using Busybox
- Android物聯網開發細致入門與最佳實踐
- CentOS 6 Linux Server Cookbook
- Ubuntu Linux操作系統實用教程
- Linux 從入門到項目實踐(超值版)
- 鴻蒙入門:HarmonyOS應用開發
- 電腦辦公(Windows10+Office2016)從新手到高手