## This section is for policies that Security Governance manages and aren't Controlled Documents. This should remain near the Controlled Documents section.
A penetration test is a process to identify security vulnerabilities in an application or infrastructure in order to evaluate the security of the system.
## Purpose
@@ -45,7 +48,7 @@ Penetrationn test results are documented and distributed to appropriate team mem
### Remediation
Findings from penetration tests are assessed and addressed in accordance with GitLab's [Vulnerability Management Standard](vulnerability-management)(SI-2, RA-5)
Findings from penetration tests are assessed and addressed in accordance with GitLab's [Vulnerability Management Standard](/handbook/security/product-security/vulnerability-management)(SI-2, RA-5)