Skip to content
Clear Infosec

Offensive Security

What is Vulnerability Assessment?

A vulnerability assessment is a systematic review that identifies, quantifies, and prioritizes security weaknesses in systems and software, typically using automated scanning combined with expert validation. It matters because it gives organizations a prioritized view of exposure so they can remediate the most critical issues first.

Example

An authenticated scan of a web server flags an outdated library with a known critical CVE, which is then ranked above lower risk findings for patching.

Reference: NIST ↗

Related Clear Infosec services

Related terms

Have a question about vulnerability assessment in your environment? Talk to our team.