Skip to main content
Institute of Advanced Technological and Commercial Studies

Skills

Running a penetration test and reporting it

Penetration testing assesses a defence by exercising it, within an authorised and documented scope. Reconnaissance, exploitation, privilege escalation, then a prioritised report: this is the skill that turns vague worry into a costed remediation plan.

Testing a defence, then explaining it

A penetration test is judged by its report as much as by its findings. A chief executive reads a ranking of risks, a cost of remediation and a deadline; an administrator reads the exact reproduction of the flaw. Writing both is half the job. The other half is the framing: written scope, signed authorisation, intervention window, data preservation. The programme teaches both, because a test conducted outside its scope commits whoever runs it.

  • Frame an engagement: written scope, authorisation, intervention window
  • Map an exposed attack surface and rank the entry points
  • Reproduce an exploit and measure its real impact
  • Write a report readable by both the board and the technical teams

Where you practise it

Each block combines input, workshop and assessed output. The year shown tells you when in the programme the skill actually comes into play.

Teaching blockProgrammeTaught hoursYear
Penetration testingCybersecurity programme — Bac+5 level220 hYear 2
Application securityCybersecurity programme — Bac+5 level120 hYear 1
Security fundamentalsCybersecurity programme — Bac+5 level220 hYear 1

Your level of command, stated plainly

You run a full penetration test under written mandate and deliver a prioritised remediation plan from it. A skill is best stated by what it lets you carry out on your own, on completion.

teaching blocks
3

Catalogue rule: one credit is twenty-five hours of work, ten of them taught.

of taught instruction
560 h
credits in total
56
professional qualifications concerned
2

The programmes that teach it

Durations, levels and real fees, read from the official catalogue when this site is built.

ProgrammeLevelDurationFees
Cybersecurity programme — Bac+5 levelMaster's degree2 years7 500 000 GNF per year

The frameworks that carry it

The framework lists the blocks to be validated. This skill appears there as a professional requirement.

Professional qualificationTarget occupationLevelTaught volume
Chief Information Security OfficerCISO7 · Expert and executive700 h
Enterprise ArchitectIS architect7 · Expert and executive700 h

Before you decide

Is the legal framework covered during the training?

It opens the block: written authorisation from the client, scope, confidentiality of findings and the fate of collected data. That is what makes the exercise professional.

What do the practical exercises run against?

Against dedicated laboratory environments reproducing complete enterprise architectures, with their network equipment and their applications.

Does this skill lead to a specific role?

It forms one block of the information systems security manager qualification, at level 7, prepared over 700 taught hours.

Running a penetration test and reporting it — Skills | IHETC — IHETC