A vulnerability assessment is often an ongoing exercise that is repeated at regular intervals. However, for a given time period, a vulnerability assessment does have a specific start point and an endpoint irrespective of what type of test is performed. Thus, in order to ensure a successful vulnerability assessment, a detailed plan is necessary. The plan can have several elements as follows:
- Overview: This section provides a high-level orientation for the test plan.
- Purpose: This section states the overall purpose and intent of conducting the test. There may be some regulatory requirements or any explicit requirement from the customer.
- Applicable laws and regulations: This section lists all the applicable laws and regulations with respect to the test being planned. These may include local as well as international laws.
- Applicable standards and guidelines...