Reconnectingβ¦
Security Assessment with Partial Data
IntermediateEvaluate security posture when scan results conflict with manual analysis.
60 min
Lab: blackboard
4 objectives
3 evidence types
security
assessment
easm
uncertainty
compliance
60
Minutes
4
Objectives
3
Evidence Types
4
Success Criteria
Case Narrative
Security Assessment with Partial Data π
Scenario π
Youβre conducting an External Attack Surface Management (EASM) assessment
for target-company.com. Your automated security scanners have completed
their analysis, but the results are inconsistent:
- Vulnerability Scanner A: 12 high-risk vulnerabilities found
- Vulnerability Scanner B: 3 medium-risk vulnerabilities found
- Manual Analysis: Identified 1 critical business logic flaw
- Compliance Framework: NIS2 requirements indicate 85% compliance
- ZKB Assessment: Czech framework shows 78% compliance
Your Challenge π
Synthesize these conflicting assessment results into a unified security rating
and risk profile. Consider:
- Scanner reliability - Different tools have different accuracy rates
- False positive rates - Some findings may not be exploitable
- Business context - Not all vulnerabilities have equal business impact
- Compliance requirements - Regulatory frameworks have specific weights
- Manual analysis insights - Human expertise vs. automated findings
What Youβll Learn π
- Multi-scanner result correlation techniques
- Risk scoring with incomplete information
- Compliance framework integration
- Business impact assessment methods
- Security rating methodology
Success Criteria π
- Produce unified security rating (A-F grade)
- Justify scanner result discrepancies
- Map findings to compliance frameworks
- Provide confidence intervals for assessments
Learning Objectives
1
Master multi-source security assessment
2
Learn risk scoring under uncertainty
3
Practice compliance framework integration
4
Develop business impact analysis skills
Required Evidence
Risk Correlation
Not collected yet
Compliance Mapping
Not collected yet
Business Impact
Not collected yet
Case Details
- Difficulty
- Intermediate
- Duration
- 60 min
- Lab Type
- blackboard
- Slug
- security-assessment-partial-data
Prerequisites
- basic-security-knowledge
Success Criteria
Compliance Mapping Complete
Required
Confidence Intervals Provided
Required
Min Discrepancy Explanations
3
Security Rating Provided
Required
Tags
security
assessment
easm
uncertainty
compliance