Assessment as an ongoing practice.
WHY ONCE IS INSUFFICIENT
Systems change, new vulnerabilities are published, and a test reflects one moment.
WHAT TO ESTABLISH
A schedule proportionate to risk and change.
WHAT DETERMINES FREQUENCY
How much the systems change How exposed they are What data they hold What requirements apply
WHAT TO TEST AFTER
Significant changes New deployments Infrastructure changes Incidents
WHY AFTER CHANGES
Most new weaknesses are introduced by change.
WHAT TO ESTABLISH
Assessment as part of the release process for significant changes.
WHY AS PART OF IT
Testing after release means shipping weaknesses.
WHAT CONTINUOUS MEASURES TO ESTABLISH
Regular automated scanning Patch management Configuration monitoring Review of new exposures
WHY BETWEEN TESTS
Annual testing leaves long periods unmonitored.
WHAT TO VARY
The provider, occasionally.
WHY
Different testers find different things, and familiarity produces repetition.
WHAT TO ESTABLISH
Whether findings are reducing over time.
WHAT REPEATED FINDINGS INDICATE
That remediation is not being sustained, or that causes are not addressed.
WHAT TO MEASURE
Findings by severity, over time Time to remediate Proportion of previous findings resolved New findings of the same type
WHY THAT LAST MEASURE
It shows whether the underlying practice improved.
WHAT TO REVIEW
Whether the scope still matches the systems you have.
WHY
Systems are added and forgotten, and unassessed systems are where compromise occurs.
WHAT TO MAINTAIN
An inventory of what exists.