A summary of the security testing documentation will help you to communicate with stakeholders. The report should not only list the security findings but also how they were identified, the testing scope, the methodology, and also mitigation suggestions. It's a common practice for an independent security testing firm to produce such documentation. The PCI DSS Penetration Test Guidance suggests a Penetration Test Report Outline as follows:
- Executive summary
- Statement of Scope
- Statement of methodology
- Segmentation test results
- Findings
- Tools used
Serpico is a penetration testing report generator, which can help to produce such a document. Although Serpico doesn't import the security testing results from tools, it allows users to select security findings/mitigation's based on templates. Follow...