Task Descriptor: Conduct Security Assessment
This task describes the main steps performed during a security assessment run.
Based on Method Task: Conduct Security Assessment
Relationships
InputsMandatory: Optional: External:
  • None
Outputs
Steps
Configure Automated Security Scan
Configure your security scan following the security test policy in place and the security test plan, based on the characteristics of your test target.
Run Security Scan
Execute the security scan according to the plan.
Verify Results and Remove False Positives
Perform a preliminary analysis of the results, and remove the duplicates and the false positives.
Conduct Additional Manual Tests (optional)
Based on the initial findings, you might need to perform additional manual tests trying to expose more vulnerabilities and identify more potential risks.
Exploit Vulnerabilities (optional)
Exploit the identified vulnerabilities and verify the risks.
Create a List of Identified Vulnerabilities
Document the findings and the preliminary analysis.
Properties
Predecessor
Multiple Occurrences
Event Driven
Ongoing
Optional
Planned
Repeatable