We are now done with day 10, the last day in this penetration testing bootcamp, so let us recap. First, we talked about gathering all that data that we had been collecting over the entire engagement. This included taking the unstructured data and putting it into a structured layout that allows for easier migration toward the end product.
Risk, and how important it is to define it, was the next topic at hand. I referenced the NIST risk standard to help show how risk is defined, as well as showing how risk can change, with an example of the same vulnerability in two different environments.
Next, we touched on the structure of the penetration test, which is arguably one of the most important sections in this chapter. Here, I laid out the various sections within the penetration report, which are listed as follows:
- Table of Contents
- Executive Summary
- Scope of Project
- Objectives...