Term:Vulnerability Scanning

From FISMApedia
Jump to: navigation, search

GAO-09-232G

Vulnerability Scanning - Type of network security testing that among others enumerates the network structure and determines the set of active hosts and associated software and verifies that software (e.g., operating system and major applications) is up-to-date with security patches and software version.

NIST SP 800-115

Vulnerability Scanning - A technique used to identify hosts/host attributes and associated vulnerabilities.