VA/PT
In past chapters, there were references to risk management and how to deal with vulnerability, among other things. What happens quite often, in terms of vulnerabilities in a company, is related to a technological gap, in which the most relevant (and therefore unsecure aspects, is related to missing updates. In this case, vulnerability management is the only thing you can do to have a clear view of the company perimeter.
VA
VA (short for Vulnerability Assessment) is a methodical analysis of an information system’s security flaws. It assesses the system’s susceptibility to known vulnerabilities, gives severity ratings to those vulnerabilities, and advises remedy or mitigation as necessary.
Among the risks that may be averted by VA are as follows:
- SQL injection, XSS injection, and more code injection threats
- The elevation of privileges as a result of flawed authentication techniques
- Software that comes with unsafe settings, such as guessable...