The executive report
The executive report, a type of assessment report, is shorter and more concise to point out a high-level view of the penetration testing output from a business strategy perspective. The report is prepared for C-level executives within a target organization (CEO, CTO, CIO, and so on). It must be populated with some basic elements, as follows:
- Project objective: This section defines the mutually agreed criteria for the penetration testing project between you and your client.
- Vulnerability risk classification: This section explains the risk levels (critical, high, medium, low, and informational) used in the report. These levels should clearly differentiate and highlight the technical security exposure in terms of severity.
- Executive summary: This section briefly describes the purpose and goal of the penetration testing assignment under the defined methodology. It also highlights the number of vulnerabilities discovered and successfully exploited.
- Statistics: This section details...