DEV Community

What a VAPT report should hand back to your dev team

A penetration test is only useful if developers can act on the result. A long PDF of scanner output does not help anyone ship a fix. Here is what a development team should expect from a vulnerability assessment and penetration test (VAPT), based on how the security team at Affix Center in Mumbai runs these engagements.

What gets tested

  • Infrastructure, applications and APIs, not only the public website
  • Secure configuration reviews of the systems the app runs on
  • Controlled penetration testing, so production is not put at risk

What you should get back

  • A risk-ranked report, so the team knows what to fix first
  • Remediation steps for each finding
  • Both an executive report and a technical report, because managers and developers need different detail
  • A retest after the fixes, to confirm they worked

Controls worth building in before the test

  • A secure development lifecycle
  • Authentication and authorisation on every API
  • Encryption at rest and in transit
  • Role-based access, with audit and compliance traceability

How often

Run VAPT at least once a year, and again after any major change to an application or to infrastructure.

If your organisation faces NIC or CERT-In empanelled security audits, plan time to fix the observations those audits raise. That work usually lands on the development team.

More detail on scope and process: Cyber Security and VAPT services by Affix Center

Written by the team at Affix Center, an IT services company in Lower Parel, Mumbai.

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to