Don't Confuse Vulnerability Scanning With Penetration Testing
A common mistake that creates false confidence — and how to use both tools effectively for ISO 27001.
Updated 10 Mar 2026
The Mistake
Many organisations run automated vulnerability scans and believe they've done penetration testing. These are fundamentally different activities, and auditors know the difference.
Vulnerability Scanning
What It Is
Automated tools scanning systems for known vulnerabilities against a database of signatures.
What It Does Well
•Identifies missing patches
•Finds known misconfigurations
•Covers large numbers of systems quickly
•Can run frequently (weekly or daily)
•Provides baseline security hygiene metrics
What It Doesn't Do
•Exploit vulnerabilities to confirm real risk
•Find business logic flaws
•Test authentication and authorisation properly
•Chain vulnerabilities together
•Think creatively like an attacker
Penetration Testing
What It Is
Skilled testers actively attempting to exploit vulnerabilities, simulating real attack scenarios.
What It Does Well
•Validates whether vulnerabilities are actually exploitable
•Finds complex attack chains
•Tests business logic and access controls
•Provides realistic risk assessment
•Identifies issues scanners miss entirely
Limitations
•Point-in-time assessment
•Coverage depends on scope and tester skill
•More expensive and time-consuming
•Can't run as frequently
What ISO 27001 Expects
The standard doesn't mandate penetration testing specifically, but:
•A.8.8 — Management of technical vulnerabilities
•A.8.34 — Protection of information systems during audit testing
You need a vulnerability management programme. Most auditors expect to see both scanning and periodic penetration testing as part of a mature programme.
A Practical Approach
•Vulnerability scanning Weekly automated scans of all systems, with defined SLAs for remediation based on severity
•Penetration testing Annual external test at minimum; more frequently for critical internet-facing systems
When presenting to auditors, be clear about which type of assessment you've done. Calling a vulnerability scan a "pentest" undermines credibility.
Related Modules
Standard Controls
Risk Register
Related Controls / Clauses
A.8.8
A.8.34
A.8.9
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.