13 hours 9 minutes
hello and welcome to another penetration testing, execution Standard discussion. Today we're going over what I think is one of the most important components of any report, and that is the executive summary. So today, the primary objective is to discuss what an executive summary is,
as well as an example summary layout that was provided by the Pee test standard.
So the executive summary will communicate to the reader the specific goals of the penetration test and the high level findings of the testing exercise. Remember the audience of the executive summary?
Our decision makers, individuals that may not be security savvy folks that have oversight and strategic vision and, you know, their overall going to be aware of the security program, pushing management, pushing initiatives and objectives.
But there may be other individuals in the organization that are not tied to cyber security or tied to understanding that language that may need to consume it like a CEO or a CEO or a CFO. So the executive summary is meant to be the information that will help them to make decisions
and ensure that they reduced risk according to their risk tolerance and their risk appetite.
Now, a summary layout will involve the following sections. You'll have a background and so this should explain to the reader the overall purpose of the test Details on the terms identified within the pre engagement section relating to risk countermeasures. Testing goals should be present to connect the reader to the overall test objectives
and the relative results.
Remember, if you can explain it without some details here, if you can cut down on certain lingo and you can simplify it and make it direct, that is the goal overall posture of the organization. So this will be a narrative of the overall effectiveness of the test and the pen testers ability to achieve the goals set forth within the pre engagement session.
We'll get into risk ranking in a risk profile, and so this can be a score qualitative quantitative in nature that will be identified and explained in this area. And so in the pre engagement section, you will need to identify scoring mechanism and the individual mechanism for tracking and grading risk.
Various methods from fear and dread and other custom rankings
can be consolidated into environmental scores and defined, and so you need to give them a number. You need to give them a metric and where they can measure where they sit, the client and where they can improve and how they can improve and what that looks like. General findings are not getting into the deep, deep technical,
but providing the synopsis of the issues found during the test. In a basic and statistical format,
graphic representations of the target's tested testing results, processes, attacks in areas, success rates and other trend doble metrics, as defined with Ian pre engagement meeting, should be present. In addition, the cause of the issue should be presented in an easy to read format. Again, we're dealing with individuals
who are decision makers
who have often times limited capacity as faras for meetings and things of that nature because they've got so much to do and so keeping it simple, keeping it concise, keeping it direct and making it informative are the key goals of your executive summary.
Now, the recommendation summary is the section of the report that should provide the reader with a very high level understanding of the tasks needed to resolve the risks,
um identified, and the general level of effort required to implement the resolution path suggested So the section will also identify the waiting mechanism used to prioritize the order of the road map. Following so strategic road map is what follows that
and that road map should include a prioritized plan for remediation of the insecure items found and should be weighed against the business objectives, level of potential impacts, all that thing, the things we were evaluating. Criticality of systems
risk levels of systems should be MATT directly to the goals identified, as well as the threat matrix created in the Pee Test Threat modeling section.
Now, by breaking up into predefined time objective based goals, the section will create a path of action to following various increments. And so this is great for a decision maker because you're not only telling them what the problem is, you're not only showing them what the problem is, you're defining for them what you think would be the best practice
progression in moving through the problems and addressing them based on metrics based on numbers based on a weight based on a risk. It's not just we feel that 12 and three is beneficial. We say we know 12 and three is beneficial because these were critical systems and they do X, y and Z for the organization, and we think they can be addressed in this manner.
And this is the order in which we think it should be done.
So all of that information should culminate into an executive summary. If you could keep this report under 15 pages, 10 pages as minimal as possible to convey the information is beneficial if you throw a
ah 35 45 55 page report in front of an executive team and you expect that to be read and you expect that to be consumed and taken into
their minds and understood
you're living a dream there. At that point, you've got to keep it again concise. I think that anything under 15 pages is best 20 pages maximum when you're putting together such a summary. So that's why it's important to be concise, be direct and just give them exactly what they need to make a decision, recommendations and all.
So let's do a quick check on learning.
True or false. The executive summary should include all technical details as laid out in every aspect of the penetration test and the efforts that we took is the tester.
Well, if you need some additional time, please pause the video. This is a false statement. So the executive summary should not include all technical details that should be concise to the point and general with respect to the information and feedback that is provided. So in summary, we discussed what an executive summary waas
and we discussed an executive summary layout example. Now again,
you can go out and find any number of reporting templates and structures to use. Just make sure that you're consistent and you're at least delivering best practice information to the team that you're creating the report for. So with that in mind, I want to thank you for your time today, and I look forward to seeing you again soon.