The audience that would be reading your penetration testing report is a very crucial part of the penetration test. We can divide the audience into three different categories:
1. Executive class
2. Management class
3. Technical class
While writing a report, you must understand which audience would read which part of your report; for example, the company’s CEO would not be interested in what exploit you used to gain access to a particular machine, but on the flip side, your developers will probably not be interested in the overall risks and potential losses to the company; instead, they would be interested in fixing the code and therefore in reading about detailed findings. Let’s briefly talk about the three classes.
Executive Class
this category includes the CEOs of the company. Since they have a very tedious schedule and most of the times have less technical knowledge, they would end up reading a very small portion of the report, specifically the executive summary, remediation report, etc., which we will discuss later in this chapter.
Management Class
Next, we have the management class, which includes the CISOs and CISSPs of the company. Since they are the ones who are responsible for implementing the security policy of the company, they would probably be a bit more interested in reading about overall strengths and weaknesses, the remediation report, the vulnerability assessment report, etc.
Technical Class
this class includes the security manager and developers, who would be interested in reading your report thoroughly. they would investigate your report as they are responsible for patching the weaknesses found and for making sure that the necessary patches are implemented.
Comments
Post a Comment