{"id":607,"date":"2026-08-11T12:35:49","date_gmt":"2026-08-11T12:35:49","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=607"},"modified":"2026-08-11T12:35:49","modified_gmt":"2026-08-11T12:35:49","slug":"vulnerability-assessment","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/","title":{"rendered":"Vulnerability Assessment: Process, Types and Reports"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: VULNERABILITY ASSESSMENT\n     Same design system as the VAPT, MFA, Penetration Testing and ISO 27001 pages.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A vulnerability assessment is a point-in-time review that finds known weaknesses across your systems, confirms which ones are real, and ranks them so the team knows what to fix first.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Testing &amp; scanning<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A vulnerability assessment identifies and rates known weaknesses across applications, networks and cloud infrastructure. It combines automated scanning with human review to remove false positives and to rate each finding by the risk it presents in your environment. It does not attempt to exploit what it finds.<\/p>\n<\/div>\n\n<p>The distinction that matters is intent. An assessment aims for coverage: it looks at everything in scope and produces a ranked list. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration test<\/a> aims for proof: it takes a smaller scope and demonstrates what an attacker could actually achieve.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#process\">How an assessment runs<\/a><\/li>\n    <li><a href=\"#rating\">Rating what you find<\/a><\/li>\n    <li><a href=\"#types\">Types of assessment<\/a><\/li>\n    <li><a href=\"#deliverable\">What you should receive<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs assessments<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"process\">How an assessment runs<\/h2>\n\n<p>Four stages. The third is where the value sits: tools produce volume, a person decides what that volume means.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 160\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Assessment stages: discover assets, scan, validate and rate, report.\">\n  <defs><marker id=\"vaA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n  <rect x=\"12\" y=\"34\" width=\"166\" height=\"80\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"95\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">1. Discover<\/text>\n  <text x=\"95\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">What actually exists,<\/text>\n  <text x=\"95\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">including forgotten systems<\/text>\n  <line x1=\"184\" y1=\"74\" x2=\"200\" y2=\"74\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vaA)\"\/>\n\n  <rect x=\"202\" y=\"34\" width=\"166\" height=\"80\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"285\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">2. Scan<\/text>\n  <text x=\"285\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Check against known<\/text>\n  <text x=\"285\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">vulnerability databases<\/text>\n  <line x1=\"374\" y1=\"74\" x2=\"390\" y2=\"74\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vaA)\"\/>\n\n  <rect x=\"392\" y=\"34\" width=\"166\" height=\"80\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"475\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">3. Validate<\/text>\n  <text x=\"475\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Drop false positives,<\/text>\n  <text x=\"475\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">rate by risk in context<\/text>\n  <line x1=\"564\" y1=\"74\" x2=\"580\" y2=\"74\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vaA)\"\/>\n\n  <rect x=\"582\" y=\"34\" width=\"166\" height=\"80\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"665\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">4. Report<\/text>\n  <text x=\"665\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Ranked list, assets,<\/text>\n  <text x=\"665\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">named remediation<\/text>\n\n  <text x=\"380\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">No exploitation at any stage. That is what separates it from a penetration test.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<div class=\"callout\">\n  <p class=\"k\">Assessment or penetration test?<\/p>\n  <p>If a customer or auditor has asked for <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">evidence<\/a> that weaknesses were exploited, they want a penetration test. An assessment answers a different question: how exposed are we across everything we own, right now.<\/p>\n<\/div>\n\n<h2 id=\"rating\" class=\"c-sage\">Rating what you find<\/h2>\n\n<p>CVSS measures severity in the abstract and knows nothing about your environment. A critical on an internal tool with no data is less urgent than a medium on a public payment service.<\/p>\n\n<p>So rate every finding on two questions. <strong>How likely is it to be exploited?<\/strong> That covers whether the asset is reachable and whether an exploit exists. <strong>What does the business lose if it is?<\/strong> That covers the data and the revenue behind the asset. Plot the answers on a grid and the order to fix things becomes obvious: the top right corner first, the bottom left last.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 370\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Nine cell risk grid. High likelihood with high impact is fix now. Low likelihood with low impact is track only.\">\n  <text x=\"380\" y=\"26\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">WHAT TO DO WITH EACH FINDING<\/text>\n\n  <rect x=\"238\" y=\"46\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#fbe9dc\"\/>\n  <text x=\"312\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">Plan<\/text>\n  <rect x=\"390\" y=\"46\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#6b4576\"\/>\n  <text x=\"464\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Fix now<\/text>\n  <rect x=\"542\" y=\"46\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#6b4576\"\/>\n  <text x=\"616\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Fix now<\/text>\n\n  <rect x=\"238\" y=\"120\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#e3f0e9\"\/>\n  <text x=\"312\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Track<\/text>\n  <rect x=\"390\" y=\"120\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#fbe9dc\"\/>\n  <text x=\"464\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">Plan<\/text>\n  <rect x=\"542\" y=\"120\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#6b4576\"\/>\n  <text x=\"616\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Fix now<\/text>\n\n  <rect x=\"238\" y=\"194\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#e3f0e9\"\/>\n  <text x=\"312\" y=\"236\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Track<\/text>\n  <rect x=\"390\" y=\"194\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#e3f0e9\"\/>\n  <text x=\"464\" y=\"236\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Track<\/text>\n  <rect x=\"542\" y=\"194\" width=\"148\" height=\"70\" rx=\"8\" fill=\"#fbe9dc\"\/>\n  <text x=\"616\" y=\"236\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">Plan<\/text>\n\n  <text x=\"224\" y=\"88\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">High<\/text>\n  <text x=\"224\" y=\"162\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Medium<\/text>\n  <text x=\"224\" y=\"236\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Low<\/text>\n  <text x=\"120\" y=\"155\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#0f1538\" transform=\"rotate(-90 120 155)\">Likelihood of exploitation<\/text>\n\n  <text x=\"312\" y=\"288\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Low<\/text>\n  <text x=\"464\" y=\"288\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Medium<\/text>\n  <text x=\"616\" y=\"288\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">High<\/text>\n  <text x=\"464\" y=\"310\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#0f1538\">Business impact if exploited<\/text>\n\n  <rect x=\"238\" y=\"330\" width=\"14\" height=\"14\" rx=\"4\" fill=\"#6b4576\"\/>\n  <text x=\"260\" y=\"342\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Fix now: this sprint<\/text>\n  <rect x=\"400\" y=\"330\" width=\"14\" height=\"14\" rx=\"4\" fill=\"#fbe9dc\"\/>\n  <text x=\"422\" y=\"342\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Plan: schedule it<\/text>\n  <rect x=\"540\" y=\"330\" width=\"14\" height=\"14\" rx=\"4\" fill=\"#e3f0e9\"\/>\n  <text x=\"562\" y=\"342\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Track: log and review<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>CVSS gives you a rough position on the horizontal axis only. The vertical axis has to come from someone who knows the system.<\/figcaption>\n<\/figure>\n\n<h2 id=\"types\" class=\"c-apri\">Types of assessment<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Type<\/th><th>What it examines<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Network<\/strong><\/td><td>Exposed services, open ports, outdated software and weak protocols across internal and external hosts<\/td><\/tr>\n    <tr><td><strong>Application<\/strong><\/td><td>Web and API surfaces, checked against known vulnerability classes and misconfigurations<\/td><\/tr>\n    <tr><td><strong>Cloud configuration<\/strong><\/td><td>IAM permissions, storage exposure, security groups, encryption and logging coverage<\/td><\/tr>\n    <tr><td><strong>Host and endpoint<\/strong><\/td><td>Operating system patch level, installed packages, local configuration and security agents<\/td><\/tr>\n    <tr><td><strong>Database<\/strong><\/td><td>Access rights, default credentials, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption at rest<\/a> and patch status<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"deliverable\" class=\"c-plum\">What you should receive<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Ranked findings<\/p>\n    <p>Ordered by risk in your environment, not by raw CVSS score alone.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Affected assets<\/p>\n    <p>The specific host, endpoint or service each finding applies to.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Named remediation<\/p>\n    <p>The version to upgrade to or the setting to change, not general advice.<\/p>\n  <\/div>\n<\/div>\n\n<p>Several hundred unfiltered findings means the triage was handed to your team. Ask how false positives are handled before engaging anyone.<\/p>\n\n<h2 id=\"osto\">How Osto runs assessments<\/h2>\n\n<p>Osto&#8217;s scanner rates findings by severity, maps them to affected endpoints and produces remediation reports on a schedule. Because assessment sits in the same platform as the WAF, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> and code security, a finding can be read alongside whether a control is already blocking it, which changes how urgent it is.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">See your exposure across everything you own<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Scheduled assessment across applications, APIs, endpoints and cloud, with findings ranked by what they actually put at risk.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Runs on a schedule &middot; Findings ranked in context &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a vulnerability assessment?<\/summary>\n  <p>A vulnerability assessment is a point-in-time review that identifies known weaknesses across applications, networks and cloud infrastructure, removes false positives, and rates each finding by the risk it presents. It does not attempt to exploit the weaknesses it finds.<\/p>\n<\/details>\n\n<details>\n  <summary>How is it different from a penetration test?<\/summary>\n  <p>An assessment prioritises coverage and produces a ranked list across everything in scope. A penetration test prioritises proof, taking a narrower scope and demonstrating what an attacker could achieve. Auditors asking for a penetration test will not accept an assessment report.<\/p>\n<\/details>\n\n<details>\n  <summary>How is it different from a vulnerability scan?<\/summary>\n  <p>A scan is the automated step that produces raw output. An assessment is the wider exercise that includes the scan, then validates the results, removes false positives and rates the remaining findings in context.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should an assessment be run?<\/summary>\n  <p>Continuously or at least monthly for scanning-driven assessment, and after any significant infrastructure change. Annual assessment alone leaves too long a window for a product that ships frequently.<\/p>\n<\/details>\n\n<details>\n  <summary>Is CVSS enough to prioritise fixes?<\/summary>\n  <p>No. CVSS rates severity in the abstract and knows nothing about your environment. Prioritisation needs a second input: whether the affected asset is exposed, whether it holds sensitive data, and whether an existing control already limits the risk.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration Testing<\/a> &middot; CVSS &middot; CVE<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability assessment is a point-in-time review that finds known weaknesses across your systems, confirms which ones are real, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[193],"class_list":["post-607","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-vulnerability-assessment"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=607"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/607\/revisions"}],"predecessor-version":[{"id":609,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/607\/revisions\/609"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/608"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}