![]() |
VOOZH | about |
A systematic process used to identify and evaluate potential risks within information systems. Purpose focuses on detecting weaknesses that could be exploited and ensuring the protection of data confidentiality, integrity, and availability.
Vulnerability assessments | Penetration tests |
|---|---|
Identification and evaluation of potential vulnerabilities | Real world attacks are simulated to exploit vulnerabilities |
Usage of manual techniques and automated systems to scan systems | Ethical hackers are involved who attempt to exploit vulnerabilities |
Various aspects of the system are covered | Target specific vulnerabilities and attack vectors |
Conducted regularly as part of an ongoing strategy | Less frequent and is performed when needed |
Gives a broader perspective of potential issues | Gives deeper insight into the impact of exploiting vulnerabilities |
Proactive approach which helps prevent potential issues | Reactive approach which assess the effectiveness of existing security measures |
For more details refer Differences between Penetration Testing and Vulnerability Assessments