For the complete documentation index, see llms.txt. This page is also available as Markdown.

πŸ“šGlossary <WIP>

Reference common terms and acronyms that are used in this guide.

Executive Summary

A document that includes a summary of the report that can be shared with external customers and shareholders as proof of completion for the pentest.

For more information, see Viewing and downloading reports and executive summaries.


Component

A category to assign to specified findings during a pentest.

For more information, see Project components.


Finding

A vulnerability discovered by Software Secured during a pentest. Each finding has its own unique identifier in the pentest report.


Intercepting Proxy

A tool that allows testers to intercept, inspect, modify, and send HTTP requests to a server in order to test for different vulnerabilities.


Pentest Director

The primary tester who will conduct your pentest. This tester will also be your main point of contact during the test if you have any questions. Other testers might be involved in your test depending on the scope, timeframe, and complexity.


Penetration Test

An authorized test that simulates real-world attacks on a product to determine the state of its security and compliance. Often abbreviated as pentest.


Production Environment

The live environment for a product that can be accessed externally by clients. Production environments are tested during network and infrastructure tests; production can be tested during other types of tests as well, but those tests have higher risks for outages and data deletion.

For more information, see Preparing your environment for the testing team.


Report

The results of the pentest that includes detailed information about Software Secured's findings.

For more information, see Viewing and downloading reports and executive summaries.


Retest/retesting

A service where Software Secured retests vulnerabilities that we previously reported to see if you remediated them successfully.

For more information, see Retesting your vulnerabilities.


SLA

Service Level Agreement

For more information, see Service Level Agreements (SLAs).


Staging/test environment

A non-production environment for a product that can only be accessed internally. These environments are typically where development is tested. In general, Software Secured tests these non-production environments to minimize risk for outages and data deletion on the production environment.

For more information, see Preparing your environment for the testing team.


Vulnerability

A flaw or weakness in a system or product that can be exploited by attackers. Sometimes used interchangeably with finding or issue.

Last updated

Was this helpful?