Reading and Understanding Findings Print

  • 0

Making sense of the report.

WHAT A REPORT SHOULD CONTAIN

Executive summary Scope and methodology Findings, each with severity Evidence Remediation guidance What was not tested

WHY WHAT WAS NOT TESTED

It establishes the limits of the assurance.

WHAT EACH FINDING SHOULD INCLUDE

What it is Where it was found How it was verified What an attacker could achieve How to fix it

WHY THE IMPACT STATEMENT

Severity without context does not support prioritisation.

WHAT TO ASSESS FOR EACH FINDING

Whether it is genuine Whether it applies in your context What it would actually allow How difficult it would be to exploit What it would cost to fix

WHY YOUR CONTEXT

A finding rated critical generically may be low risk behind other controls, and the reverse is also true.

WHAT TO QUESTION

Findings you do not understand Severity ratings that seem wrong Remediation advice that is impractical

WHY

The tester should be able to explain and justify each one.

WHAT TO ESTABLISH

A discussion of the report with the tester.

WHY

Reports delivered without discussion are frequently misread.

WHAT TO PRIORITISE

Issues that are externally exploitable Issues affecting sensitive data Issues that are easy to exploit Issues that are cheap to fix

WHY THAT LAST ONE

Quick fixes reduce exposure immediately.

WHAT TO AVOID

Treating the report as a list to be completed in order Fixing only what is easy Disputing findings to avoid work

WHAT TO PRODUCE

A remediation plan with owners and dates.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot