What is the difference between Vulnerability Assessment and Penetration Testing?
By Paul Rummery, Securenet Consulting

Think of a vulnerability assessment as the first step to a penetration test. 
The information churned from the assessment will be used in the testing(PT). Whereas, the assessment is checking for holes and potential vulnerabilities, the penetration testing actually attempts to exploit the findings from assesments. 

1. Vulnerability Assessments are designed to yield a prioritised list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritising them. 

2. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access/test in realtime and see the reality of there security posture. Exploit critical infrastructure, tell the company how you got in, and, if possible ways to prevent it from happening again. 


The last part of the pentest or a vulnerability assessment is easily the most important -- the reporting aspect. Good pentesters can find almost any way into a network. However, they need to tell you how they got in and how to prevent it from occurring again. Likewise, any vulnerability scanning engine you use will allow you to spew out a report, but without actually verifying the data and/or determining what vulnerabilities are actually exploitable or constitute risk to the organisation, its mostly useless.

---------------------------------------------------------------------------------------------------------------
 

WANT TO LEARN MORE? Contact Securenet Consulting