What testing is for.
WHAT SECURITY ASSESSMENT IS
Authorised examination of systems to identify weaknesses before someone else does.
WHAT IT IS NOT
Unauthorised testing of anything A guarantee of security A substitute for building securely
WHY AUTHORISATION IS ABSOLUTE
Testing systems without permission is unlawful, regardless of intent, and it is prosecuted.
WHAT FORMS ASSESSMENT TAKES
Vulnerability scanning: automated identification of known weaknesses
Penetration testing: attempting to exploit weaknesses, within an agreed scope
Configuration review Code review Architecture review Social engineering assessment, where authorised
WHY THE DISTINCTION MATTERS
Scanning finds known issues cheaply; testing establishes whether they are actually exploitable.
WHAT ASSESSMENT PROVIDES
Knowledge of where you are weak Evidence for those who require it Prioritisation of remediation
WHAT IT DOES NOT PROVIDE
Assurance that nothing remains Security itself
WHY THAT MATTERS
A test finds what it looked for, within its scope, at that moment.
WHAT DETERMINES VALUE
Scope Competence of the tester Whether findings are actually fixed
WHY THAT LAST POINT
Reports that are filed rather than acted upon achieve nothing.
WHAT TO TREAT THIS CATEGORY AS
Guidance on commissioning, scoping and acting on authorised assessment.