Automated identification.
WHAT SCANNING DOES
Checks systems against a database of known vulnerabilities and misconfigurations.
WHAT IT PROVIDES
Broad coverage, quickly and cheaply Regular repeatable assessment Identification of missing patches
WHAT IT DOES NOT PROVIDE
Verification that findings are exploitable Discovery of logic flaws Understanding of business impact Findings requiring human reasoning
WHY VERIFICATION MATTERS
Scanners report issues that do not apply, and they miss issues that do.
WHAT FALSE FINDINGS PRODUCE
Effort spent on nothing, and eventual disregard of all findings.
WHAT TO ESTABLISH
That findings are verified before remediation effort is committed.
WHAT TO SCAN
External systems, regularly Internal systems, periodically Applications, where the scanner supports it
HOW OFTEN EXTERNALLY
Frequently, because exposure is continuous.
WHAT TO ESTABLISH
That scanning is scheduled and that results are reviewed.
WHY REVIEWED
Scans producing reports nobody reads are a cost with no benefit.
WHAT TO PRIORITISE
Issues that are externally reachable Issues with known exploitation Issues affecting sensitive systems
WHAT TO BE CAUTIOUS OF
Rating by the scanner alone.
WHY
Severity ratings are generic and they do not account for your context.
WHAT TO ASSESS
Whether the issue matters here.
WHAT TO ESTABLISH ABOUT AUTHENTICATED SCANNING
Whether the scanner has credentials to examine systems properly.
WHY
Unauthenticated scanning sees far less.
WHAT TO TRACK
Findings over time Whether they are being resolved Recurring issues
WHAT RECURRENCE INDICATES
A process problem rather than a technical one.