Scope
A call to agree what is in scope, what is excluded, when scans may run, and who needs to know. It is written down before anything is scanned.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// VULNERABILITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA
An insurer's questionnaire asks when you last scanned. A customer review wants the results. A contract clause points at vulnerability monitoring and scanning. Or a penetration test is on the budget and nobody has run a scan yet. This is the scan, done properly, with the findings ranked and a plan to fix them.
Authenticated and unauthenticated scanning of a scope agreed in writing first: servers, workstations, network gear, firewalls, and the security systems on the same network where they are in scope. An unauthenticated scan shows what something on your network can see from outside a system. An authenticated scan logs in and finds what the outside view cannot, such as missing patches and weak settings. Both are run, with proper tools.
It is a one-time engagement with a start, a report, and an end. If you need scans on a cycle afterwards, the vulnerability management add-on is the ongoing option.
A penetration test bought before a single vulnerability scan has been run helps nobody. The scan finds the known weaknesses first, so a penetration tester is not paid to rediscover them. Run the scan first, fix what it finds, and buy the penetration test afterwards if the contract or the risk calls for one.
Your IT provider shouldn't be assessing its own work, because some won't tell on themselves. If a provider says it does vulnerability management for you, or that its tool says you're secure, verify it with your own scan. A sales-oriented assessment tool run by a provider may tick the box, and it is still a sales tool.
I don't resell hardware or software and I don't take commissions, so a finding here is never a sales opportunity. See the independence policy.
Five phases, delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.
A call to agree what is in scope, what is excluded, when scans may run, and who needs to know. It is written down before anything is scanned.
Authenticated and unauthenticated scans of the agreed scope with proper tools. Run remotely, through the DHD where the network cannot otherwise be reached.
Findings are checked, false positives are removed, and what is left is ranked by what each system does for the business, not by scanner score alone.
A remediation plan with an owner and a date against every item that needs fixing, written for your team or your IT provider to work from.
After the fixes, the fixed items are scanned again and the report is updated with before and after results.
CPCSC requirement 03.11.02, vulnerability monitoring and scanning, asks you to scan on a cycle and fix what the scans find inside a defined window. The same requirement sits in NIST SP 800-171, which CMMC builds on. Progress is what an assessor wants to see: last scan, results, what's remediated, and the next scan date. Read the requirement in plain language at CPCSC risk assessment.
The network against a standard: segmentation, the firewall rule base, switch configurations, and remote access.
A rule-by-rule review of one firewall or HA pair, with a ranked findings list.
Scans on a cycle, triage, and a remediation tracker, run alongside managed care or on its own.
A vulnerability assessment scans an agreed scope for known weaknesses and ranks what it finds. A penetration test is a separate exercise that tries to exploit weaknesses. Run the scan first and fix what it finds, so a penetration tester isn't paid to rediscover known problems.
An unauthenticated scan shows what something on your network can see from outside a system. An authenticated scan logs in and finds what the outside view cannot, such as missing patches and weak settings. I run both, with proper tools.
The scope sets the work, so it's agreed on a scoping call and written down before anything is scanned. A written quote comes before any work starts.
Yes. All 5 phases are delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.
CPCSC requirement 03.11.02, vulnerability monitoring and scanning, asks you to scan on a cycle and fix what the scans find inside a defined window. The same requirement sits in NIST SP 800-171, which CMMC builds on. An assessor wants to see the last scan, the results, what was remediated, and the next scan date.
Your IT provider shouldn't be assessing its own work, because some won't tell on themselves. If a provider says its tool shows you're secure, verify it with your own scan. I don't resell hardware or software and I don't take commissions, so a finding here is never a sales opportunity.
Bring the questionnaire or the clause that triggered this and a rough list of what is in scope, and a short call confirms the scope.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.