Chapter 6. Going Further

Introduction

Vulnerability assessment (VA) represents a key element of an organization’s information security program. A VA highlights an organization’s security liabilities and helps asset owners, security managers, and business leaders determine information security risk. VAs only report vulnerabilities, though. They don’t substantiate that vulnerabilities actually exist; penetration tests do that.

The past few chapters discussed the tools, ...

Get The Best Damn IT Security Management Book Period now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.