A good penetration testing report can be broken down into the following elements:
- Page design
- Document control
- Cover page
- Document properties
- List of the report's contents
- Table of contents
- List of illustrations
- Executive/high-level summary
- Scope of the penetration test
- Severity information
- Objectives
- Assumptions
- Summary of vulnerabilities
- Vulnerability distribution chart
- Summary of recommendations
- Methodology/technical report
- Test details
- List of vulnerabilities
- Likelihood
- Recommendations
- References
- Glossary
- Appendix
Here is a brief description of some of the relevant sections:
- Page design: This refers to the choice of fonts, headers and footers, colors, and other design elements that are to be used in the report. ...