Concept and mechanism
Security testing starts with authorization and rules of engagement. Define targets, permitted methods, timing, impact limits, stopping criteria, and contacts. Technical reachability does not establish permission to test a third party’s system. Then choose techniques answering the question: scanning identifies candidates, an authorized exercise may demonstrate exploitation, and configuration review examines declared or effective controls. Techniques complement each other. A version banner may differ from a backport; validate patch evidence and relevant behavior before closing as false positive or confirmed flaw. Record conditions so another team can understand the conclusion’s reach.
Guided application
No findings in a public scan does not mean authenticated functions were assessed. Compare executed coverage with acceptance criteria and make exclusions visible. If 18 of 20 known findings were fixed, that is 90% remediation of that set, not 90% security of the entire organization. Retain denominator, period, and scope in reporting. For an AI model, also define abuse and quality tests with their own criteria; success on a small example set does not establish behavior in every context. Independent review can reuse implementer evidence but must meet policy-defined independence. At release review, address gaps through additional authorized testing or formal scope change. Avoid broadening conclusions to meet a date because RUN will inherit the very paths that were not demonstrated.
The contract requires authenticated administration testing, but the report covers only public login: the requirement remains unproven.
Common pitfalls
No findings treated as no risk; implicit scope; percentage without denominator; changing report author treated as independence.
Related topics: Operations, incidents, and recovery · Secure software and supply chain
Useful evidence shows what was assessed, how, with what result, and with which limitations.
Reference: Technical Guide to Security Testing and Assessment · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29