Summary of findings
This is very similar to the executive summary in terms of the audience level. This should be a relatively small section that includes a high-level summary of what was found. I tend to favor a graphic that displays what is found. A picture is worth 1,000 words, and I completely agree with this statement. A color-coded pie chart with a breakdown of the risks will very quickly summarize the urgency of the report. Use the same language and classification as you use for the risk rating, as well as color coding. Consistency is key. Be sure to only state the facts here and not any opinionated statements. This is really just high-level facts.
Some penetration testers prefer to show a summary of the tests performed as opposed ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access