risk
Inadequate vulnerability scanning and pre-release testing
Software released without adequate testing, and no regular vulnerability scanning or penetration testing, leaves exploitable defects undiscovered until they manifest — or are exploited — in production.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Vulnerability & Patch Management
- Secure Development (SDLC) & Application Security
- taxonomy
- iso-27005-vulnerability
- inherent_rating
- medium
Details
- risk_id
- vuln-inadequate-testing-scanning
- category
- cyber_security
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-VULN-02 — Test security through independent penetration exercises mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Independent penetration testing is the operative defense against the absence of pen testing, validating exploitability.
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Obtaining evidence of security testing for outsourced deliverables ensures third-party code is tested/scanned rather than shipped untested.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Authenticated scans on a defined cadence are the operative control against absent or irregular vulnerability scanning.
- UC-CONFIG-04 — Build security and privacy into software design and upkeep mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Pre-release security testing directly mitigates releasing software with undiscovered exploitable defects.
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Requiring test and approval before implementation directly mitigates releasing inadequately tested software.
- UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- related
- rationale
- A coordinated external vulnerability-disclosure channel surfaces exploitable defects that inadequate internal testing missed.
- UC-VULN-04 — Test software security during development and acceptance mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandatory security testing at development and acceptance directly prevents software shipping without adequate testing.
- UC-SDLC-05 — Enforce secure coding and input validation standards mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Verifying adherence via code review and static analysis before release is the pre-release security testing itself.
- UC-SDLC-02 — Plan and resource development programs and projects mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- related
- rationale
- Allocating budget/resources for security work funds the testing/tooling that is otherwise cut for cost, an enabler of adequate testing.
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandatory testing in non-production before approval/migration directly prevents releasing inadequately tested software to production.
- UC-SDLC-01 — Follow a secure development lifecycle with approval gates mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Mandated security activities and test/approval gates before release ensure software is tested rather than shipped untested.
- UC-SDLC-07 — Approve, test, and accept changes before production release mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- related
- rationale
- A mandatory acceptance-test gate prevents inadequately-tested software from reaching production.