Reporting and QA

How testers support findings with evidence and give clients recommendations they can use.

Reporting explains what the test established and what the client needs to do. QA checks that the evidence supports the conclusions and that material limitations are visible.

Recommended readingOffensive security glossary

Use these points when reviewing the work

  1. Trace each finding from claim to evidence.
  2. Review severity logic separately from prose quality.
  3. Make assumptions, scope, and limitations visible.
  4. Test whether recommendations are specific and usable.
  5. Feed repeated defects into coaching and process improvement.

Browse the other delivery topics.

The article collection covers related reporting and management decisions.