18B: List Report Contents Flashcards
4.1 Compare and contrast important components of written reports.
This is a part of the written report, and is a high level and concise overview of the penetration test, its findings, and their impact. This will typically be geared toward the c-suite.
executive summary
A high-level description of the standards or framework followed to conduct the penetration test.
methodology
A detailed explanation of the steps taken while performing the activity.
attack narrative
A strategic assessment of what level of residual risk is tolerable for an organization.
risk appetite
The process of assigning quantitative values to the identified risks.
risk rating
The process of adjusting the final rating of vulnerabilities to the client needs.
risk prioritization
Systematic activity that identifies organizational risks and determines their effect on ongoing, mission critical operations.
business impact analysis (BIA)
Quantifiable measurements of the status of results or processes.
metrics
The specific data points that contribute to a metric
measures
The possible solution to the issue identified during the penetration test.
remediation