Vulnerability assessment is the structured evaluation of an organisation’s systems against known weaknesses, producing a prioritised inventory of exposures and recommended mitigations. It is typically scope-bounded and recurring, using automated scanners and authenticated checks to map findings to severity and asset criticality. Mandated by many cybersecurity standards, it provides the baseline evidence for compliance and continuous risk reduction.
Content
- Assessments combine network and host scanning, credentialed configuration checks, and validation against vulnerability databases (CVE/NVD), feeding remediation workflows and compliance reporting under frameworks such as ISO 27001 and PCI DSS. They differ from penetration testing by emphasising breadth of coverage and repeatability over depth of exploitation.