From the course: ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 24,600 courses taught by industry experts.

Analyzing scan reports

Analyzing scan reports

- [Instructor] As a cybersecurity analyst you'll probably spend a good amount of your time analyzing reports from vulnerability scans. One of your primary responsibilities will be sorting through the results of these scans and presenting information from them to a variety of audiences. You'll need to provide engineers, developers and administrators with the technical detail that they need to correct issues. You'll need to explain trends and high level risk ratings to business leaders and you'll need to present security management with a picture of how well the organization is doing at managing risk. As you interpret the results of any scan report, you should first focus on five factors that we've already discussed. The severity of the vulnerability, the criticality of the systems affected, the sensitivity of the information involved, the difficulty of remediation and the exposure of the system with the vulnerability.…

Contents