Security Assessment with Partial Data

Intermediate

Evaluate security posture when scan results conflict with manual analysis.

60 min Lab: blackboard 4 objectives 3 evidence types
security assessment easm uncertainty compliance
60
Minutes
4
Objectives
3
Evidence Types
4
Success Criteria

Case Narrative

Security Assessment with Partial Data πŸ”—

Scenario πŸ”—

You’re conducting an External Attack Surface Management (EASM) assessment
for target-company.com. Your automated security scanners have completed
their analysis, but the results are inconsistent:

  • Vulnerability Scanner A: 12 high-risk vulnerabilities found
  • Vulnerability Scanner B: 3 medium-risk vulnerabilities found
  • Manual Analysis: Identified 1 critical business logic flaw
  • Compliance Framework: NIS2 requirements indicate 85% compliance
  • ZKB Assessment: Czech framework shows 78% compliance

Your Challenge πŸ”—

Synthesize these conflicting assessment results into a unified security rating
and risk profile. Consider:

  1. Scanner reliability - Different tools have different accuracy rates
  2. False positive rates - Some findings may not be exploitable
  3. Business context - Not all vulnerabilities have equal business impact
  4. Compliance requirements - Regulatory frameworks have specific weights
  5. Manual analysis insights - Human expertise vs. automated findings

What You’ll Learn πŸ”—

  • Multi-scanner result correlation techniques
  • Risk scoring with incomplete information
  • Compliance framework integration
  • Business impact assessment methods
  • Security rating methodology

Success Criteria πŸ”—

  • Produce unified security rating (A-F grade)
  • Justify scanner result discrepancies
  • Map findings to compliance frameworks
  • Provide confidence intervals for assessments

Learning Objectives

1
Master multi-source security assessment
2
Learn risk scoring under uncertainty
3
Practice compliance framework integration
4
Develop business impact analysis skills

Required Evidence

Risk Correlation Not collected yet
Compliance Mapping Not collected yet
Business Impact Not collected yet

Case Details

Difficulty
Intermediate
Duration
60 min
Lab Type
blackboard
Slug
security-assessment-partial-data

Prerequisites

  • basic-security-knowledge

Success Criteria

Compliance Mapping Complete Required
Confidence Intervals Provided Required
Min Discrepancy Explanations 3
Security Rating Provided Required

Tags

security assessment easm uncertainty compliance