// VULNERABILITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA

Vulnerability assessment

An insurer's questionnaire asks when you last scanned. A customer review wants the results. A contract clause points at vulnerability monitoring and scanning. Or a penetration test is on the budget and nobody has run a scan yet. This is the scan, done properly, with the findings ranked and a plan to fix them.

What it covers

Authenticated and unauthenticated scanning of a scope agreed in writing first: servers, workstations, network gear, firewalls, and the security systems on the same network where they are in scope. An unauthenticated scan shows what something on your network can see from outside a system. An authenticated scan logs in and finds what the outside view cannot, such as missing patches and weak settings. Both are run, with proper tools.

It is a one-time engagement with a start, a report, and an end. If you need scans on a cycle afterwards, the vulnerability management add-on is the ongoing option.

Not a penetration test

A penetration test bought before a single vulnerability scan has been run helps nobody. The scan finds the known weaknesses first, so a penetration tester is not paid to rediscover them. Run the scan first, fix what it finds, and buy the penetration test afterwards if the contract or the risk calls for one.

Kept at arm's length from your IT provider

Your IT provider shouldn't be assessing its own work, because some won't tell on themselves. If a provider says it does vulnerability management for you, or that its tool says you're secure, verify it with your own scan. A sales-oriented assessment tool run by a provider may tick the box, and it is still a sales tool.

I don't resell hardware or software and I don't take commissions, so a finding here is never a sales opportunity. See the independence policy.

What you receive

  • A findings report ranked by risk to the business
  • A remediation plan with an owner and a date on every item
  • A rescan of what was fixed, with before and after results
  • A record an assessor or insurer can read: the last scan, the results, what was remediated, and the next scan date

How it runs

Five phases, delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.

PH-01

Scope

A call to agree what is in scope, what is excluded, when scans may run, and who needs to know. It is written down before anything is scanned.

PH-02

Scan

Authenticated and unauthenticated scans of the agreed scope with proper tools. Run remotely, through the DHD where the network cannot otherwise be reached.

PH-03

Rank

Findings are checked, false positives are removed, and what is left is ranked by what each system does for the business, not by scanner score alone.

PH-04

Plan

A remediation plan with an owner and a date against every item that needs fixing, written for your team or your IT provider to work from.

PH-05

Rescan

After the fixes, the fixed items are scanned again and the report is updated with before and after results.

CPCSC Level 2 and CMMC

CPCSC requirement 03.11.02, vulnerability monitoring and scanning, asks you to scan on a cycle and fix what the scans find inside a defined window. The same requirement sits in NIST SP 800-171, which CMMC builds on. Progress is what an assessor wants to see: last scan, results, what's remediated, and the next scan date. Read the requirement in plain language at CPCSC risk assessment.

Who it's for

  • Defence suppliers and subcontractors working toward CPCSC Level 2 or CMMC
  • Organizations answering an insurer or customer questionnaire that asks about scanning
  • Anyone about to buy a penetration test who has not scanned yet
  • Organizations that want a check that is independent of the provider that runs their IT

Related work

VA-02

Firewall review →

A rule-by-rule review of one firewall or HA pair, with a ranked findings list.

Questions

What's the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment scans an agreed scope for known weaknesses and ranks what it finds. A penetration test is a separate exercise that tries to exploit weaknesses. Run the scan first and fix what it finds, so a penetration tester isn't paid to rediscover known problems.

What's the difference between an authenticated and an unauthenticated scan?

An unauthenticated scan shows what something on your network can see from outside a system. An authenticated scan logs in and finds what the outside view cannot, such as missing patches and weak settings. I run both, with proper tools.

How much does a vulnerability assessment cost?

The scope sets the work, so it's agreed on a scoping call and written down before anything is scanned. A written quote comes before any work starts.

Can the scan be done remotely?

Yes. All 5 phases are delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.

Does a vulnerability assessment help with CPCSC Level 2 or CMMC?

CPCSC requirement 03.11.02, vulnerability monitoring and scanning, asks you to scan on a cycle and fix what the scans find inside a defined window. The same requirement sits in NIST SP 800-171, which CMMC builds on. An assessor wants to see the last scan, the results, what was remediated, and the next scan date.

Why shouldn't my IT provider run the scan?

Your IT provider shouldn't be assessing its own work, because some won't tell on themselves. If a provider says its tool shows you're secure, verify it with your own scan. I don't resell hardware or software and I don't take commissions, so a finding here is never a sales opportunity.

Book a scoping call

Bring the questionnaire or the clause that triggered this and a rough list of what is in scope, and a short call confirms the scope.