Back to Glossary

Security testing method

Penetration Testing

Controlled simulation of an attack to identify Vulnerabilities and evaluate their practical impact on a defined target.

Related domain: CybersecurityConcept ID: concept-penetration-testing

Definition

Penetration Testing is a controlled method for evaluating the security of systems, applications or infrastructure by simulating the actions of a potential attacker to identify Vulnerabilities and assess their practical impact.

Human Explanation

Specialists conduct an authorised and controlled attack against a defined target to determine whether weaknesses could be exploited by a real attacker.

Why it Matters

Penetration Testing provides evidence about practical exposure and the effectiveness of implemented Security Controls.

Conceptual Boundary

Penetration Testing is neither random error hunting nor automated Vulnerability scanning. It is a planned, authorised and controlled engagement that includes analysis and attempts to exploit identified weaknesses within an agreed scope.

Practical Perspective

A penetration test creates value only when its findings lead to appropriate remediation and verification that the identified exposure has been reduced.

Related Concepts