Inspect before downloading
See what is inside
These previews come from the published bundle files, so you can judge the method and writing before using it.
Deliverable guide
Security Assessment / Pen-Test Report source-backed guide
Defines a source-backed report contract for authorized security assessment and penetration-test evidence.
Read the fileOverview
Security Assessment / Pen-Test Report overview
Use this bundle to structure a report after authorized security testing or assessment. It does not authorize testing, exploitation, access, disclosure, or remediation.
Read the fileIs this bundle right for your task?
Who it is for
- People drafting, reviewing, approving, or relying on Security Assessment / Pen-Test Report
- Teams working in software, saas, information security
When to use it
- A Security Assessment / Pen-Test Report draft needs a clear purpose, audience, evidence base, structure, and approval path.
- An existing draft needs unsupported claims, missing sections, unresolved decisions, and reviewer comments addressed.
What you need to provide
- The document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action.
- Existing drafts, templates, policies, examples, terminology, and review criteria that the output must follow.
Tasks and expected outputs
Questions it helps answer
- structure a reviewable security assessment report
- separate tester evidence from business risk decisions
- prevent invented findings, severity, remediation, and authorization claims
What it helps produce
- security assessment report
- penetration-test report
- finding review
Practical example
Use it with an agent
Load the bundle as context, provide the evidence named above, then adapt this example to your situation.
Provide the document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action. Ask the agent to draft or review Security Assessment / Pen-Test Report and return security assessment report with material claims tied to evidence and assumptions, open questions, reviewers, and approval gates marked. Begin with NIST SP 800-115, then confirm that the reference is current and applicable. Inspect Security Assessment / Pen-Test Report source-backed guide before drafting.
Context path: bundles/deliverables/security-assessment-report
What the bundle includes
Frameworks
- NIST SP 800-115
- OWASP WSTG
- PTES reporting
- CVSS v4.0
Evaluations
- security assessment report quality check
Sources used to build this bundle
These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.
Limitations and safe use
Do not use this for
- Publishing, approving, or acting on a draft before its material claims, source evidence, owners, and approval gates have been reviewed.
Known limitations
- This bundle is a drafting and review aid, not authorization to test systems, legal or regulatory advice, an audit opinion, or proof of remediation.
- Local scope, authorization, affected assets, evidence, dates, severity inputs, business impact, owners, deadlines, retest results, and approvals require current supplied or inspected evidence.
- Do not infer findings, CVSS vectors, risk ratings, compliance status, remediation state, or accountable reviewers.
Safety notes
- Minimize and redact sensitive evidence, secrets, credentials, personal data, and client identifiers.
- Require explicit confirmation before disclosure, external distribution, risk acceptance, remediation-state changes, or live-system action.
- Treat the bundle as a source-backed drafting aid and route qualified security, legal, privacy, compliance, and risk decisions to accountable reviewers.