Offensive Security
What is Vulnerability Assessment?
A vulnerability assessment is a systematic review that identifies, quantifies, and prioritizes security weaknesses in systems and software, typically using automated scanning combined with expert validation. It matters because it gives organizations a prioritized view of exposure so they can remediate the most critical issues first.
Example
An authenticated scan of a web server flags an outdated library with a known critical CVE, which is then ranked above lower risk findings for patching.
Reference: NIST ↗
Related Clear Infosec services
Related terms
Have a question about vulnerability assessment in your environment? Talk to our team.