Cybersecurity Glossary

What is a Vulnerability Assessment?

A vulnerability assessment systematically examines a defined scope for known vulnerabilities, unsafe configurations and missing controls. It combines automated detection with expert validation and risk assessment. The result is not an unchecked scanner list but a prioritized account: Which weakness affects which asset, what impact is realistic, and how should it be remediated?

What is the purpose of a vulnerability assessment?

The assessment makes the current vulnerability state of a defined area visible and actionable. It may cover external systems, internal networks, cloud configurations, endpoints, web applications or a particular business process. The question must therefore be clear before work begins: Is the objective known CVEs, hardening, external exposure, regulatory evidence or a baseline for improvement?

An assessment is a point-in-time view. It describes the state during the assessment period and within the agreed scope. New deployments, configuration changes and newly disclosed vulnerabilities can alter the result immediately.

How does an assessment work?

  1. Agree objectives and scope: Define assets, environments, credentials, time windows, exclusions and required assurance.
  2. Inventory assets: Complete systems, services, technology, ownership and business criticality.
  3. Perform checks: Combine automated scanning, configuration comparison and selected manual tests.
  4. Validate findings: Remove false positives, confirm affected versions and test technical prerequisites.
  5. Assess risk: Consider exposure, exploitability, impact, controls and current threat activity.
  6. Plan treatment: Assign owners to patches, configuration changes, compensating controls or justified acceptance.
  7. Retest remediation: Verify important fixes technically and record residual risk.

Which assessment methods are combined?

MethodContribution to the assessment
Asset discoveryFinds reachable systems and differences from the known inventory.
Vulnerability scanningChecks many assets repeatedly for known technical issues.
Authenticated reviewIdentifies packages, patch state and local security configuration more accurately.
Configuration reviewCompares settings against vendor guidance or an approved baseline.
Manual validationConfirms important findings, prerequisites and actual exposure.
Document and interview reviewAssesses controls that are not completely visible through technical testing.

The mix depends on the objective. An internet-perimeter assessment needs different checks from a review of container images or an Active Directory environment. An automated scan can form part of an assessment but does not automatically constitute one.

How are vulnerabilities prioritized?

CVSS provides a useful technical starting point but does not represent complete organizational risk. A sound assessment adds asset criticality, reachability, required privileges, available exploits, known active exploitation, affected data and existing controls. Several individually moderate findings may also combine into a critical attack path.

  • Treat immediately:
    Actively exploited or readily reachable critical flaws on important assets.
  • Plan short-term:
    Relevant weaknesses with a realistic attack path but existing barriers or controls.
  • Remediate routinely:
    Limited risks, hardening measures and low-exposure issues.
  • Accept or monitor:
    Only with a documented rationale, owner, expiry date and trigger for reassessment.

What belongs in the report?

A good report records scope, timing, methodology, credentials used, limitations and unreachable assets. Each finding should contain affected systems, technical evidence, root cause, realistic impact and concrete remediation. An executive summary explains systemic risks, patterns and prioritized next steps. Machine-readable exports can support ticketing but do not replace a clear explanation.

Vulnerability assessment or penetration test?

CharacteristicVulnerability assessmentPenetration test
Primary objectiveIdentify and prioritize vulnerabilities systematicallyDemonstrate realistic attack paths and impact safely
BreadthOften many assets and known controlsOften narrower scope with greater technical depth
ExploitationPrimarily validation and limited exploitationManual exploitation and chaining within the rules
Typical useRecurring visibility and vulnerability managementValidation of critical systems and complex attack paths

The methods complement one another. Recurring assessments provide breadth; a penetration test examines selected targets more deeply and is more likely to identify business-logic, authorization and chained flaws.

How often should an assessment be performed?

Frequency follows risk and change rate. Internet-facing, frequently deployed or especially critical systems require closer review than stable isolated assets. Additional triggers include major releases, migrations, new cloud environments, acquisitions and newly disclosed critical vulnerabilities. Continuous scanning can bridge formal assessments but also requires ongoing analysis.

Which mistakes reduce its value?

Incomplete asset lists, failed scanner credentials and unchecked tool output create false assurance. Prioritization based solely on CVSS, findings without owners and reports without retesting are equally problematic. An assessment becomes effective only when validated risks lead to traceable actions whose completion is verified.

Penetration Tests

Uncover Security Vulnerabilities

Professional penetration testing for your business

Web Apps
Networks
Mobile Apps
10% New Customer Discount
Plan Now

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on Vulnerability Assessment? Tell us!