Defense

Vulnerability Assessment

A systematic review that identifies, classifies and prioritises known weaknesses across systems.

Definition

A vulnerability assessment is a systematic process of identifying, classifying and prioritising known weaknesses across systems, applications and network infrastructure, usually supported by automated scanning.

The purpose is breadth. Where a penetration test goes deep on a narrow scope, a vulnerability assessment covers as much of the estate as possible and asks what known weaknesses exist here. It is typically run continuously or monthly rather than annually, because new vulnerabilities are published constantly.

The output is a prioritised list, and the prioritisation is the actual work. A scan across a mid-sized estate can return thousands of findings, most of which are low severity or not reachable by an attacker. Treating the raw count as the metric produces a queue nobody can clear; ranking by exploitability and business exposure produces something a team can act on.

Its limits follow from being automated and signature-driven. It finds known issues, so it will not surface a novel flaw in your own business logic, and it reports what could be wrong rather than proving what an attacker could achieve. That proof is what a penetration test adds, which is why the two are complementary rather than alternatives.

At a glance

Type
Assessment activity
Also known as
VA, vulnerability scanning, penilaian kerentanan

How it works

  1. 1

    Asset discovery: establish what actually exists, since unknown assets cannot be assessed

  2. 2

    Scanning: automated tools check systems against databases of known vulnerabilities

  3. 3

    Validation: false positives are removed, because unverified findings waste remediation effort

  4. 4

    Prioritisation: findings are ranked by severity, exploitability and business exposure

  5. 5

    Remediation and rescan: fixes are applied and verified, then the cycle repeats

Key points

  • Breadth is the point; a vulnerability assessment covers the estate rather than going deep on one target
  • Prioritisation matters more than the total finding count
  • It identifies known weaknesses only, so novel and logic flaws are out of reach
  • It reports what could be wrong; a penetration test proves what an attacker could do
  • Asset discovery is the foundation, because an unknown system is never scanned

Best practices

  • Run continuously or monthly rather than annually, since new vulnerabilities appear constantly
  • Keep an accurate asset inventory, as coverage gaps are usually inventory gaps
  • Validate findings before assigning remediation work
  • Rank by exploitability and exposure, not by severity score alone
  • Track time-to-remediate as the operational metric, not the number of open findings

Real-world example

An Indonesian insurer's monthly scan returns 4,000 findings and the security team reports the number to management, who ask for it to reach zero. Re-ranking by internet exposure and exploitability reduces the genuinely urgent set to 23 items, which are cleared in a fortnight. The count never reached zero, and the risk fell sharply anyway.

How Claro helps

Vulnerability assessment covers technical weaknesses; it has no view of the workforce. The equivalent discipline for people is measuring susceptibility to social engineering over time. Claro provides that, with per-user risk scoring and department-level trends that can be reported alongside technical findings.

Frequently asked questions

What is a vulnerability assessment?

A systematic process of identifying, classifying and prioritising known weaknesses across systems, applications and infrastructure, usually supported by automated scanning. Its value is breadth of coverage and a ranked list of what to fix first.

What is the difference between a vulnerability assessment and a penetration test?

An assessment is broad, automated and frequent, and reports what known weaknesses might be exploitable. A penetration test is narrow, manual and periodic, and proves what an attacker could actually achieve by chaining weaknesses together. They answer different questions and are complementary.

How often should a vulnerability assessment run?

Continuously or monthly for most organisations. New vulnerabilities are published constantly, so an annual assessment leaves long periods where newly disclosed issues go undetected.

Is a high finding count a sign of poor security?

Not necessarily. Large estates generate large counts, and most findings are low severity or unreachable. A more useful measure is time-to-remediate for findings that are genuinely exploitable and exposed.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo