Validation Operations
Everything continuous in the CyberOptix CTEM Platform runs on its own - scanning, cloud assessment, breach monitoring. Validation Operations covers the work that is scheduled and performed by people: penetration tests, phishing campaigns, assessments, reviews.
An engagement is one such piece of work. It has a type, a schedule, people doing it, and findings that come out of it.
Engagement types
| Type | What it is |
|---|---|
| Penetration test | A full assessment |
| Web application test | Initial assessment of an application |
| Web application delta test | Re-assessment covering what changed |
| API assessment | Assessment of an API |
| Phishing campaign | Simulated phishing against your people |
| Breach and attack simulation | Exercising defences against known techniques |
| Threat modelling | Structured analysis of a design |
| Cloud engineering | Cloud-focused assessment work |
| SOC review | Review of security operations |
| Retest | Confirming previous findings are fixed |
Delta tests and retests are worth knowing about, because they are cheaper than a full assessment and answer the question people actually have after one. A delta test covers what changed since the last assessment; a retest confirms specific findings are fixed.
The lifecycle
An engagement moves through a defined sequence, and each step is a deliberate handoff:
| Status | Means |
|---|---|
| Requested | Asked for, not yet agreed |
| Approved | Agreed to go ahead |
| Scheduled | Has dates |
| In progress | Being performed |
| Delivered | Results handed over |
| Accepted | You have acknowledged delivery |
| Closed | Finished |
| Cancelled | Ended without completing |
Two distinctions that earn their place:
Approved is not Scheduled. Agreeing to the work and having dates for it are different states, and conflating them hides the gap where most delay actually happens.
Delivered is not Accepted. Delivery is the provider handing over results; acceptance is you confirming you have them and they are what was agreed. Keeping them separate means "we sent it" and "they have it" are distinguishable - which matters when an engagement is contractual.
Findings from an engagement
Findings raised during an engagement link to it and land in the same queue as everything else, with the same severity, statuses and SLAs. See Findings and triage.
That linkage is what makes a retest straightforward: the engagement knows which findings it produced, so confirming them is a defined scope rather than a rediscovery exercise.
Notes
Engagements carry notes recording what was done and when. These are written by the people performing the work, which keeps the record of an assessment attached to the assessment rather than living in email.
Calendar
The calendar shows scheduled engagements over time.
SCREENSHOT: the engagement calendar.
Its practical use is avoiding collisions: an assessment during a change freeze, a phishing campaign in the same week as a security awareness push, two engagements competing for the same team. Those are all cheap to avoid in advance and disruptive to discover late.
Scanners and appliances
The infrastructure that performs automated assessment - scanners, apex appliances - is covered under Deployment, not here. This section is about the work; that section is about the machinery.
API
The endpoints behind this section are in the API reference.
Next
- Findings and triage - working what an engagement produces
- Deployment - the appliances that perform automated assessment
- Reports - assessment reporting