Core framework
What leaders should make visible
- Trace each finding from claim to evidence.
- Review severity logic separately from prose quality.
- Make assumptions, scope, and limitations visible.
- Test whether recommendations are specific and usable.
- Feed repeated defects into coaching and process improvement.
Recommended reading
Articles in this guide
What good QA looks like in a penetration testing team
Good pentest QA verifies the reasoning chain from scope and testing evidence to each conclusion, severity decision, recommendation, and client-facing statement. It is more than proofreading: the reviewer should be able to reproduce the logic, identify unsupported assumptions, confirm that limitations are visible, and judge whether the report enables both technical remediation and business decision-making.
Read articleHow penetration testing teams should handle severity disputes
Pentest teams should handle severity disputes as structured evidence reviews, not negotiations over a label. Separate what the test proved from technical severity, threat information, environmental context, and professional judgement. Record the original rationale, evaluate new client information consistently, and change the rating only when that information changes the documented assessment.
Read article