Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 28th August 2026 at 3:24 am #3439
A one-page letter may say a test was done without showing whether important risks remain. What should the buyer ask?
28th August 2026 at 9:11 am #3440Accepted answerCheck who tested, when they tested, which systems and interfaces were in scope, which methods were used, what was excluded, how findings were rated, and whether critical and high findings were retested after remediation. Protect sensitive details, but require enough evidence to understand residual risk and planned fixes. A test does not replace secure development or continuous vulnerability management. NIST SP 800-218 describes secure software development practices.
28th August 2026 at 11:32 am #3518Community replyHow recent should remediation evidence be if the original penetration test is almost a year old?
- AuthorPosts
- You must be logged in to reply to this topic.