Training · VA / CA · Vulnerability Assessment + Configuration Audit

Find it. Validate it. Prioritise it. Document it for the auditor.

A twelve-week practitioner programme that runs two disciplines in parallel: vulnerability assessment, from raw scanner output to a validated, risk-prioritised register; and configuration audit, from a hardening benchmark to a system you can prove is built to meet it. You work real lab tenants, production-grade scanners, and the evidence an auditor signs.

The misunderstood discipline

A scanner produces findings. A practitioner validates the real vulnerabilities. An auditor asks whether the system was ever hardened to standard. Three different jobs.

VA and CA are the two disciplines that touch every security programme, and the two most consistently misunderstood. A scanner dumps ten thousand findings; the practitioner validates the two hundred that are real; the configuration auditor checks whether the estate was ever built to a hardened standard — and whether it has drifted since. The programme trains both halves of that role.

01

"VA is just running a scanner"

Scanners produce findings. A practitioner produces a defensible risk register — validated, deduplicated, cleared of false positives, and weighted for business context. That gap is the whole discipline.

02

Config audit as a checkbox

A once-a-year checklist produces a binder no-one reads and an estate that has drifted by February. Real configuration audit measures systems against a hardening benchmark, tracks the deviations that matter, and proves the baseline still holds between cycles.

03

Two languages, one practitioner

Vulnerability teams rarely think in hardening baselines; configuration auditors rarely validate an exploit. The practitioner who can do both — find the vulnerability and prove the config that would have stopped it — is the one who gets hired and gets listened to.

Two parallel tracks. One practitioner.

VA from scanner to register. CA from benchmark to hardened baseline.

The programme runs both tracks in parallel. They cross twice — at Validation (week 5) and Reporting (week 11) — where a single piece of evidence has to satisfy the risk owner who has to fix it and the auditor who has to sign it off.

Two parallel tracks: a vulnerability-assessment pipeline on the top row and a configuration-audit pipeline on the bottom row, crossing at Validation and Reporting. VA · TECHNICAL TRACKCA · CONFIGURATION TRACKSCANauth'd + unauth'dVALIDATEPoC · false-pos cullPRIORITISECVSS + business contextTRACKregister · SLA · retestBENCHMARKCIS · STIG · vendorSCOPEhosts · images · cloudMEASUREscan · diff · driftHARDENEDgaps · fixes · retestWEEK 5 · VALIDATION CROSSOVERWEEK 11 · REPORTING12-WEEK PROGRAMME · BOTH TRACKS · WEEKLY DELIVERABLE PER TRACKCAPSTONE · A SINGLE TENANT, BOTH TRACKS, ONE INTEGRATED REPORT

What you do on the programme

Twelve weeks. Two tracks. One practitioner who can do both jobs.

Run a proper scan

Authenticated or unauthenticated, active or passive, internal or external — you build the scan plan that matches the engagement letter, not the one the tool defaults to.

Validate every finding

You run a manual proof-of-concept against every high and critical, cull the false positives, consolidate duplicates, and overlay business context — the unglamorous work that turns ten thousand rows into the two hundred that are real.

Prioritise with CVSS + context

Start from the CVSS base, apply temporal modifiers and an environmental score, then overlay the risk owner's own view. The scanner hands you a severity; your job is to justify the one you actually assign.

Audit config against the benchmark

Measure a host, image, or cloud account against its CIS Benchmark and the hardening clauses inside ISO 27001, PCI-DSS, and NIST CSF. Every deviation gets recorded, and every deviation gets traced to the control it breaks.

Prove the hardened state

Config exports, scan output, screenshots, before-and-after diffs — each one indexed, timestamped, and attached to the benchmark control it satisfies, so a hardened state is something you can show, not just claim.

Write the audit-ready report

Executive summary, scope statement, methodology, a findings narrative, a configuration-gap analysis, a risk-prioritised remediation roadmap, and a retest scope — the format an auditor will accept on the first read.

Sample week · Configuration audit · week 7 of 12

The week the auditor sits across the table from you.

A representative week auditing a single tenant in the Cyberange lab against a hardening standard. Both tracks work the same environment in parallel, and Friday's deliverable is one integrated report that satisfies the risk owner who has to remediate and the auditor who has to sign it off.

  1. Monday

    Scope + baseline lock

    Read the tenant's engagement letter, then decide which hardening baselines apply — the relevant CIS Benchmarks plus the configuration clauses of ISO 27001, PCI-DSS, and the sector regulator's framework. Document the baseline per asset class, and bound the scope with the risk owner.

  2. Tuesday

    Scan and measure

    Run authenticated vulnerability scans against the in-scope estate. In parallel, measure live configuration against the baselines — CIS-CAT runs, config exports, cloud-posture pulls. Two tracks, one tenant, same day.

  3. Wednesday

    Validate, deduplicate, contextualise

    Cull the scan output and run manual proof-of-concepts against the criticals, then cross-reference against Tuesday's configuration data: does a live vulnerability trace back to a control the benchmark said should have been hardened? More often than not, it does.

  4. Thursday

    Map to controls

    Every validated finding and every configuration deviation mapped to its ISO Annex A control, PCI requirement, NIST CSF subcategory, and CIS Benchmark item — the same issue through four lenses. The cohort cross-checks each other's mappings.

  5. Friday morning

    Write the integrated report

    Executive summary, risk-prioritised technical findings, a configuration-gap analysis mapped to the baselines, a prioritised remediation roadmap, and a retest scope — the one report a risk owner and an auditor will both accept.

  6. Friday afternoon

    Mock audit review

    An instructor — usually with prior audit-side experience — runs a mock review across the table. Your evidence, your scoping, and your control mappings all get challenged, while the cohort watches and grades.

Tooling coverage

The scanner stack, the hardening benchmarks, the framework libraries.

Vulnerability scanners

Nessus, OpenVAS/Greenbone, nuclei, trivy and grype — plus authenticated-profile engineering and writing your own NASL and nuclei template checks.

Web + API scanners

OWASP ZAP, Burp Pro (Scanner), and nuclei web templates, with the false-positive thresholds and auth-flow recording that make them usable against a real app.

Container + cloud posture

kube-bench, kube-hunter, Prowler, ScoutSuite and CloudSploit — CIS-benchmark-aligned configuration auditing across containers and cloud.

Identity + AD assessment

PingCastle, BloodHound (read-only), Purple Knight and ADRecon — posture and configuration, never exploitation.

Config baselines + evidence

CIS-CAT and OpenSCAP for benchmark scoring, config-baseline diffing, and evidence-vault patterns — workflow over vendor lock-in.

Framework libraries

ISO 27001 Annex A, PCI-DSS 4.0, NIST CSF 2.0, NIST SP 800-53, SOC 2 Trust Services Criteria, and the CIS Benchmarks.

Regulator-specific

RBI Cybersecurity Framework, SEBI CSCRF, IRDAI guidelines, CERT-In Directions, NCIIPC CII guidance, and the DPDP Act 2023.

Reporting discipline

A template library covering executive summary, scope, methodology, findings, configuration-gap analysis, remediation roadmap, retest scope, and evidence index.

What you walk away with

The practitioner who can run the assessment and sit the audit.

Validated risk-register portfolio

Three full tenant assessments, with genuine validation work and real risk-owner sign-offs in your portfolio.

Audit-ready report library

Three integrated VA and CA reports — framework-mapped, evidence-indexed, in the shape an auditor will actually accept.

Cross-framework fluency

You can move between ISO, PCI, NIST CSF, the CIS Benchmarks, and the major Indian-regulator frameworks in a single sitting — most candidates can speak one.

Hiring pipeline access

BFSI risk-and-compliance teams, MSSP assessment desks, internal-audit cyber units, and regulator-side assessment cells — reached through a referral, not a job portal.

Frameworks drilled

  • ISO/IEC 27001 · 27002
  • PCI-DSS 4.0
  • NIST CSF 2.0 · SP 800-53
  • SOC 2 Trust Services
  • CIS Benchmarks · DISA STIG
  • RBI CSF · SEBI CSCRF · IRDAI
  • CERT-In · NCIIPC · DPDP 2023

Practice

"An unvalidated vulnerability is only a finding. An unprioritised finding is only noise. And noise that no-one has tied back to a control and a fix isn't security work at all — it's paperwork waiting to get lost."
VA / CA Training · operating principleWhy real assessment work starts at validation and ends at a control — never at the scanner dump.

Twelve weeks. Two tracks. One integrated capstone.

Weekend and weekday cohorts. Corporate cohorts on request. Particularly well suited to BFSI risk-and-compliance teams, internal-audit cyber units, and MSSP assessment desks.