Here are some key points from the webcast:
- The Executive Summary (It should be understood by your mom or your wife)
- What did we do?
- Why did we do it?
- What did we find?
- How bad is it?
- How much needs to be done to fix it?
- How good will we be afterwards?
- The Findings Summary (Designed to be read by the CIO / CISO / Director-level security executives. More details than the executive summary)
- What is the severity distribution of the findings?
- What are the strengths?
- What are the weakness?
- How do we compare to last year / last time?
(For example, we can have a overall strength or overall weakness sections. A chart of comparison with last result is very helpful )
- The technical details (the questions to answer)
- How did we perform the penetration test?
- What specifically did we find?
- How can our findings be reproduced?
- What needs to be done to fix each finding?
(Present great information with diagram. Avoid too much details. )
- Design is important (Convert your information more effectively)
No comments:
Post a Comment