Points to examine
Use these points when reviewing the work
- Trace each finding from claim to evidence.
- Review severity logic separately from prose quality.
- Make assumptions, scope, and limitations visible.
- Test whether recommendations are specific and usable.
- Feed repeated defects into coaching and process improvement.
Recommended reading
Articles in this guide
What good QA looks like in a penetration testing team
Good pentest QA establishes whether the work is Actionable, Clear, Defensible and Correct. AC/DC gives testers and reviewers a shared basis for examining findings and delivery decisions. Apply it during testing as well as at report review, so missing evidence or an unexplained limitation can be addressed while the work is still in progress.
Read articleHow penetration testing teams should handle severity disputes
Review a disputed severity rating against the original evidence and any new information from the client. Keep technical characteristics distinct from environmental context and remediation priority. Apply the agreed rating method, explain any remaining assumptions and record the decision. Commercial pressure alone does not provide a basis for changing the assessment.
Read article