Lesson 18 - Summarizing Report Components Flashcards
What is the term of people not directly involved with the client but who may still be involved. Providers, investors, regulators and similar entities
Third Party Stakeholders
What is the process of assigning values to the identified risk referred to:
Also what is the scoring system that is published by NIST called
Risk Rating
Common Vulnerability Scoring System (CVSS)
What is the process of adjusting the final ratings of vulnerabilities to the client needs
Risk Prioritization
What is the post-activity that identifies organizational risk and determines their effect on ongoing, mission critical operations
Business Impact Analysis (BIA
Describe the difference between a metric and measures
Metrics are quantifiable measurements of results or processes and can be expressed on a scale say from 1 to 10.
Measures are specific datapoints that contribute to a metrics
Outline a typical and recommended format for the delivery of the PenTest
Executive summary
Scope details
Methodology
Attack narrative
Findings
Risk rating
Risk prioritization
Metrics and measures
Remediation
Conclusion
Appendix or supporting evidence