Vulnerability Assessment
A vulnerability assessment is the testing process used to identify and assign severity levels to as many security vulnerabilities or defects as possible in a defined timeframe. This process may involve automated and manual techniques with varying degrees of emphasis on comprehensive coverage. Using a risk-based approach, vulnerability assessments may target different layers of technology, the most common being server, networking, and application layer assessments.
There are 3 major objectives of vulnerability assessment.
1. Identify known and prioritize the vulnerabilities.
2. Document the vulnerabilities so that customers can easily identify and reproduce the findings.
3. Create guidance to assist customers with remediating the identified vulnerabilities.

