Appendix C. Security Assessment Sample Report

This appendix provides a template example, as shown in Table C.1, that can be used for a final report. This template outlines the information, data, and procedures for documenting a security assessment so that the results can be provided to management. The report template contains the following sections:

Note that this is an example; each organization should modify this template to meet its own existing needs. Below the template you will find guidelines and information on what each section should contain.

Note

The template example shown in the appendix is also available on the book's web page.

Table C.1. Security Assessment Sample Report

Section

Contents

Notice

Contains confidentiality notice.

Executive summary

Brief overview of the assessment and its findings.

Introduction

Discusses organization, locations, mission, and employees.

Statement of work

Defines the "what" and "how" of the assessment.

Analysis

Details what you found and how you found it.

Conclusions

Outlines what changes should be made to improve security.

Категории