1. Security Assessments Overview
- Every organization must periodically perform security assessments to discover, confirm, and remediate vulnerabilities.
- Different types suit different maturity levels, compliance needs, and threat models.
- Legacy + new vulnerabilities must always be tracked.
2. Vulnerability Assessment (VA)
- Broad, checklist-based evaluation against a security standard (GDPR, PCI-DSS, OWASP, CIS, ISO 27001, etc.).
- Goal: Identify as many known vulnerabilities as possible.
- Mainly automated scanning (Nessus, OpenVAS, Qualys, etc.) + manual validation of Critical/High/Medium findings.
- Stops at proving the vulnerability exists (no exploitation, no privilege escalation, no lateral movement).
- Suitable for ALL organizations, especially low-maturity ones.
- Usually performed monthly or quarterly.
3. Penetration Testing (Pentest)
- Simulated cyber attack with legal authorization.
- Goal: Prove exploitability and measure real business impact.
- Types:
- Black-box: zero knowledge (external attacker perspective)
- Grey-box: limited knowledge (unprivileged user/employee)
- White-box: full access to configs, source code, architecture
- Specializations: Web App, Network/Infrastructure, Mobile, API, Physical, Social Engineering.
- Requires medium to high security maturity.
- Should only start after a history of successful VA + remediation.
4. Key Differences: VA vs Pentest