Skip to main content

Validation Operations

Everything continuous in the CyberOptix CTEM Platform runs on its own - scanning, cloud assessment, breach monitoring. Validation Operations covers the work that is scheduled and performed by people: penetration tests, phishing campaigns, assessments, reviews.

An engagement is one such piece of work. It has a type, a schedule, people doing it, and findings that come out of it.

Engagement types​

TypeWhat it is
Penetration testA full assessment
Web application testInitial assessment of an application
Web application delta testRe-assessment covering what changed
API assessmentAssessment of an API
Phishing campaignSimulated phishing against your people
Breach and attack simulationExercising defences against known techniques
Threat modellingStructured analysis of a design
Cloud engineeringCloud-focused assessment work
SOC reviewReview of security operations
RetestConfirming previous findings are fixed

Delta tests and retests are worth knowing about, because they are cheaper than a full assessment and answer the question people actually have after one. A delta test covers what changed since the last assessment; a retest confirms specific findings are fixed.

The lifecycle​

An engagement moves through a defined sequence, and each step is a deliberate handoff:

StatusMeans
RequestedAsked for, not yet agreed
ApprovedAgreed to go ahead
ScheduledHas dates
In progressBeing performed
DeliveredResults handed over
AcceptedYou have acknowledged delivery
ClosedFinished
CancelledEnded without completing

Two distinctions that earn their place:

Approved is not Scheduled. Agreeing to the work and having dates for it are different states, and conflating them hides the gap where most delay actually happens.

Delivered is not Accepted. Delivery is the provider handing over results; acceptance is you confirming you have them and they are what was agreed. Keeping them separate means "we sent it" and "they have it" are distinguishable - which matters when an engagement is contractual.

Findings from an engagement​

Findings raised during an engagement link to it and land in the same queue as everything else, with the same severity, statuses and SLAs. See Findings and triage.

That linkage is what makes a retest straightforward: the engagement knows which findings it produced, so confirming them is a defined scope rather than a rediscovery exercise.

Notes​

Engagements carry notes recording what was done and when. These are written by the people performing the work, which keeps the record of an assessment attached to the assessment rather than living in email.

Calendar​

The calendar shows scheduled engagements over time.

Screenshot pending

SCREENSHOT: the engagement calendar.

Its practical use is avoiding collisions: an assessment during a change freeze, a phishing campaign in the same week as a security awareness push, two engagements competing for the same team. Those are all cheap to avoid in advance and disruptive to discover late.

Scanners and appliances​

The infrastructure that performs automated assessment - scanners, apex appliances - is covered under Deployment, not here. This section is about the work; that section is about the machinery.

API​

The endpoints behind this section are in the API reference.

Next​