Cybersecurity & resilience

Penetration testing

Published Reviewed

A penetration test is an authorised, controlled attack on systems or applications to find exploitable weaknesses before a real adversary does. It differs from a vulnerability scan by involving human judgement — chaining findings, testing business logic, and proving impact. Frameworks across the board expect it: ISO 27001 as a control choice, PCI DSS as an explicit annual requirement, DORA within its testing programme.

Läs definitionen på svenska: Penetrationstest

Also known as: Pentest · Säkerhetstest

Where this term does its work

This definition is general information, not legal advice. Always verify the current official source.