Define scope
Agree assets, access, methodology and deliverables.
Prepare evidence that relevant systems were assessed and identified risks were followed through.
Web applications, APIs, mobile applications, cloud environments and networks selected through risk-based scoping.
Assessment scope, validated findings, remediation history, revalidation results and updated reports.
Which ISMS risks, controls, systems and audit dates should inform the assessment scope?
Requirements depend on your organization, environment, selected controls, framework version and assessor. VulNetra supports the assessment lifecycle; it does not grant certification or guarantee compliance.
Discover → Validate → Remediate → Assure
Agree assets, access, methodology and deliverables.
Combine repeatable coverage with expert security judgment.
Keep ownership, guidance, comments and evidence together.
Retest applicable fixes and preserve the outcome.
Confirm the assurance driver, scope and evidence expectations before testing begins.