What is meant by a security assessment?
A security assessment is the process of evaluating the security of an IT environment, including the network and the information systems. Security administrators or third party consultants usually use software tool called a vulnerability scanner specially designed to search out the security risks and vulnerabilities on internal hosts and workstations. In addition, adequacies in operation procedures would also be evaluated as part of the security assessment. In general, a security risk assessment is conducted at the very beginning of a system deployment project to identify what security measures are required; or when there is a major change to the information assets or their environment. As new security vulnerabilities emerge from time to time, security risk assessments should be conducted regularly, for example once every two years.