Security assessments are *comprehensive reviews of the security of a system*, *application*, *or other tested environment*. During a security assessment, a trained information security professional performs a risk assessment that identifies vulnerabilities in the tested environment that may allow a compromise and makes recommendations for remediation, as needed. Security assessments normally include the use of security testing tools but *go beyond automated scanning* and manual penetration tests. They also include a thoughtful review of the *threat environment, current and future risks*, and the value of the targeted environment. The main work product of a security assessment is normally an assessment report *addressed to management* that contains the results of the assessment *in nontechnical language* and concludes with specific recommendations for improving the security of the tested environment.