Skip to main contentSkip to main content
    Back to Glossary
    security
    2 min read

    Vulnerability Assessment

    A vulnerability assessment is an automated process of identifying security weaknesses in systems, networks, and applications without actively exploiting them.

    Vulnerability assessments systematically identify security weaknesses in IT systems. Unlike penetration testing, they focus on discovery and classification without exploitation.

    Types of assessments: - Network Scanning: Identifying vulnerable services - Web Application Scanning: Finding web vulnerabilities (OWASP Top 10) - Database Scanning: Checking database configurations - Host-Based Assessment: Evaluating system configurations - Cloud Configuration Review: Assessing cloud settings

    Common tools: - Nessus, Qualys, Rapid7 (network) - OWASP ZAP, Burp Suite (web) - AWS Security Hub, GCP Security Command Center (cloud)

    Vulnerabilities are scored using CVSS (0-10 scale), with 7+ considered high severity.

    Why It Matters

    Vulnerability assessments provide continuous visibility into your attack surface, identifying weaknesses before attackers do. Compliance frameworks require regular vulnerability scanning—typically quarterly—with documented remediation timelines. Organizations that run continuous scans and remediate critical vulnerabilities within 14 days significantly reduce their breach risk compared to those relying on annual assessments.

    Key Points

    Identifies vulnerabilities without exploiting them
    Should be performed at least quarterly
    CVSS scoring helps prioritize remediation
    Automated scans need expert analysis
    Different from pen testing which involves exploitation

    Applicable Compliance Frameworks

    Related Terms

    Frequently Asked Questions

    How often should vulnerability scans be run?

    Quarterly at minimum. Many organizations run weekly or continuous scans, especially for internet-facing systems.

    What is CVSS?

    Common Vulnerability Scoring System rates severity from 0-10. Critical (9-10), High (7-8.9), Medium (4-6.9), Low (0.1-3.9).

    Need Help with Vulnerability Assessment?

    Our experts can help you understand and implement the right controls for your organization.