Skip to content

Glossary

Vulnerability assessment

A vulnerability assessment is the systematic identification, classification and prioritization of security weaknesses in systems, as a rule without actually exploiting them.

The process starts with an asset inventory, since nothing can be assessed that the organization does not know it has. Authenticated and unauthenticated scans follow, along with comparison of configurations against hardening baselines and of software versions against known-vulnerability databases. Findings receive a severity rating on a common scale (CVSS), which must be enriched with the system's exposure, evidence of real-world exploitation and the business criticality of the asset.

The difference from a penetration test is the difference between breadth and depth. A vulnerability assessment answers which weaknesses exist and where; a penetration test answers what an attacker can actually achieve by chaining them together. The assessment is largely automated, repeatable and frequent and covers the whole environment; the test is largely manual, time-boxed, focused, and validates real impact, including logic flaws that tools cannot see. Tool output must be verified manually, as false positives and false negatives are common.

Value appears only once the assessment is embedded in a continuous vulnerability management process: inventory, detection, triage, prioritization by risk rather than severity score alone, remediation or compensating control, verified closure and trend reporting. Agreed remediation deadlines by severity and a register of exceptions with justification and expiry are advisable. Systematic handling of technical vulnerabilities is also expected by the information security management standard and by European cybersecurity legislation.

Back to glossary

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.