Reporting is one of the most important phases of a penetration test since the reported vulnerabilities are not just for the technical team to use, but also management. There are generally two types of reports that need to be presented to the client – an executive report and a Detailed Technical Report (DTR).
An executive report is for the top management of the organization/company so that they can make decisions based on the business impact mentioned in the report. On the other hand, the DTR, as its name suggests, is a detailed report that outlines all the vulnerabilities that were found. This includes the suggested steps to help the technical (internal security operations and developers team) team patch the vulnerabilities. Overall, the report should contain the following details:
- Purpose and scope
- Approach and methodology used
- Common vulnerability...