# What is a Vulnerability Assessment?

> A vulnerability assessment is a scoped evaluation that identifies and analyzes weaknesses in a system, product, service, process, or defined environment.

- Canonical URL: https://yellowcube.eu/glossary/vulnerability-assessment/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It may combine automated scanning with configuration and architecture review, code or dependency analysis, interviews, evidence inspection, and limited validation. The assessment produces findings for risk decisions; it need not exploit weaknesses and is broader than a vulnerability scan.

The scope, assumptions, evidence, depth, and date of the work determine what its results mean. A useful report distinguishes observed facts from inferences, explains affected conditions and uncertainty, and gives owners enough context to choose and verify treatment.

### Key points

- **Scope and criteria:** Define the systems, environments, identities, interfaces, time window, excluded actions, evaluation criteria, and authorization before work begins.
- **Method selection:** Choose techniques suited to the target and question, such as authenticated scanning, configuration review, architecture analysis, source review, dependency analysis, or controlled manual checks.
- **Finding quality:** Confirm applicability where feasible, remove duplicates, document evidence and assumptions, rate confidence, explain potential consequences, and identify practical remediation or mitigation paths.
- **Important limitation:** An assessment is a time-bounded view shaped by its scope and methods; it cannot prove that untested components are secure, that every reported weakness is exploitable, or that remediation has succeeded without verification.

### Related terms

[Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Vulnerability scanning](<https://yellowcube.eu/glossary/vulnerability-scanning/>) · [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Threat modeling](<https://yellowcube.eu/glossary/threat-modeling/>) · [Risk assessment](<https://yellowcube.eu/glossary/risk-assessment/>)

### Sources

[NIST SP 800-115](https://csrc.nist.gov/pubs/sp/800/115/final) · [NIST glossary: Vulnerability Analysis](https://csrc.nist.gov/glossary/term/vulnerability_analysis) · [NIST SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

