Network & infrastructure / report template

Network Infrastructure Assessment Report Template & PDF Example

Use the Network Infrastructure Assessment template to document network zones, equipment and administrative boundaries. This page explains the assessment boundaries, evidence expectations and relevant references, alongside a populated PDF example and an editable Vulnotes report template.

Cover of the network infrastructure assessment sample report
17 pages · Example report · English

A reusable structure for network zones, equipment and administrative boundaries.

State approved ranges, sites, equipment, test vantage points and operational restrictions.

The report includes document control, an executive assessment, scope, coverage, environment context, a findings register, repeatable finding details and remediation tracking.

The PDF is exported from a populated demonstration report saved in Vulnotes. It includes client details, technical findings, evidence figures, CVSS scoring where applicable, severity charts, owners and retest criteria. Download the reusable template from Vulnotes Manager to use its layout and variables with your own report data.

Network Infrastructure Assessment: scope, evidence and references

The guidance below describes how to scope and document the work. It does not imply that every topic is covered by the sample PDF. Record the reference editions used in your own engagement.

Turn network scope into explicit assessment boundaries

Record sites, address ranges, network zones, equipment classes, external dependencies and approved observation points. Document whether IPv6, wireless, remote access, industrial systems and provider-managed equipment are included. An internal assessment and an external assessment do not observe the same controls.

Distinguish asset discovery, vulnerability scanning, configuration review and segmentation validation. State maintenance windows and operational restrictions. NIST SP 800-115 remains useful for planning and reporting, but its 2008 publication date means it is not a current device-hardening baseline.

Express segmentation as policy plus evidence

A segmentation observation should identify source zone, destination zone, service, expected decision, observation point and time. An allowed management connection from a user zone needs a stated access policy before its significance can be evaluated. A timeout is not, on its own, proof that a firewall rule enforced a deny.

Configuration review can explain the intended control; observation records explain what was seen from a particular location. Document routing, intermediary controls and visibility limits where they affect the conclusion. Do not turn a sampled set of paths into an unconditional claim about all traffic between two networks.

Report operational controls as well as exposure

Include administrative access, configuration backup and restoration evidence, logging destinations, time consistency and ownership where these are in scope. Preserve vendor, model and software-release context for technical recommendations. A saved backup is not evidence of a successful restoration; enabled logging is not evidence of monitoring coverage.

For remediation, identify the policy or device owner, affected service, change dependency and acceptance record. Retest the agreed boundary after the change and distinguish corrected, partially corrected, accepted and untested items. Use the scope and environment sections to keep those boundaries explicit.

Inside this example report

The 17-page PDF shows how the report is organized. Its example content illustrates the layout; adapt it to the scope and evidence of your own engagement.

  1. 01

    Document control and executive assessment

    Identify the issue, recipients, supported conclusion, priorities and verified strengths.

  2. 02

    Scope and coverage

    State approved ranges, sites, equipment, test vantage points and operational restrictions.

  3. 03

    Environment and evidence

    Connect each observation to an asset or zone, observation point, timestamp and expected policy.

  4. 04

    Findings and remediation

    Document observations, impact, correction, owner and acceptance evidence. Finding pages repeat from report findings.

  5. 05

    Retest and limitations

    Record retest results, scoring methodology, assumptions and residual uncertainty.

Read the full sample PDF

Make the report useful to its readers

Record actual coverage

Distinguish verified controls, observed gaps, untested areas and justified exclusions.

Keep the evidence traceable

Connect each observation to an asset or zone, observation point, timestamp and expected policy.

Personalize before delivery

Replace completion guidance and sample rows, enter the assessment provider, review dates and recipient list, and inspect the final export.

Make it your own in Vulnotes

  1. 1

    Download your template from Vulnotes Manager

    Sign in to Vulnotes Manager, download this template and add it to your instance. Select it when creating a report to reuse its layout, report variables and finding sections. The public PDF shows an example of the finished output.

  2. 2

    Let Vulnotes fill the connected variables

    The template includes variables connected to your report: client details, engagement dates, findings and severity statistics where used. Vulnotes fills these from the data saved in your report. Add your findings and complete assessment-specific sections such as scope, analysis and conclusions; automatic population does not replace that work. Match the finding fields and categories expected by the template.

  3. 3

    Edit the structure and visual design

    Change page layout, orientation, margins, fonts, colors, branding, headers and footers in the template editor. Edit or replace tables, chart settings, images, code blocks and section labels. Heading numbering and the table of contents can be adapted to your delivery conventions. Text embedded inside an image must be changed in the source image or replaced.

  4. 4

    Adapt the data bindings

    Report variables hold engagement-specific content. Finding loops and filters control repeatable sections; charts and score tables can use report data. Review these bindings when renaming fields or changing the finding structure. Individually authored slide summaries still need editorial updates when findings change.

  5. 5

    Write, review and deliver

    Create your report with its client, scope and dates. Replace the example content, add your findings, review the preview and export the finished document.

Three ways to create and adapt your templates

Use the template editor

Start with a Manager template or create your own in the visual editor. Change the layout, branding, content and variables, then preview the result with your report data.

Template editor documentation

Import your existing Word document

Import a DOCX report into Vulnotes as an editable template draft. Review conversion warnings and page layout, then connect report variables and finding sections before reusing it. Complex Word formatting may need adjustments.

DOCX import documentation

Create and edit through MCP

Connect an MCP-compatible assistant to Vulnotes to create templates or edit pages, elements, variables and styling. Access follows your API key permissions. Review the changes and preview the document before using it for client delivery.

MCP setup and template authoring

See which fields Vulnotes supplies automatically and how to add engagement-specific content in the report variables documentation. Browse available templates in Vulnotes Manager.

Common questions

What does the download contain?

A reusable English template from Vulnotes Manager, including its document layout, styling and report variables. Vulnotes fills connected variables from your report data; complete the assessment-specific sections and use the finding fields expected by the template.

Can I use the PDF as an audit result?

No. This is a sample deliverable. Complete the reusable template with your engagement scope, evidence and review decisions before client delivery.

Does the template establish compliance?

No. Record the reference versions, actual coverage, evidence and exclusions applicable to your engagement. A reference mapping alone does not establish compliance.

What export formats are available in Vulnotes?

Vulnotes exports reports as PDF, editable Word documents (DOCX), Excel spreadsheets (XLSX), structured report data (JSON), and ZIP archives containing the report PDF and attachments, with optional password protection. XLSX lets you select finding fields and report content sections. You can also export selected findings as a partial PDF or DOCX report. The client portal additionally offers CSV exports of findings when enabled by the administrator. Read the export documentation.