Skip to main content

πŸ’Ό CA-8 Penetration Testing (L)(M)(H)

Description​

Conduct penetration testing [FedRAMP Assignment: at least annually] on [Assignment: organization-defined systems or system components].

CA-8 Additional FedRAMP Requirements and Guidance:

Guidance: Reference the FedRAMP Penetration Test Guidance.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/ca/08
  • Internal
    • ID: dec-c-bbaaecb7

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-8 Penetration Testing3

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CA-8 Penetration Testing (L)(M)(H)
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό CA-8 Penetration Testing (L)(M)(H)2

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CA-8(1) Independent Penetration Testing Agent or Team (M)(H)
πŸ’Ό CA-8(2) Red Team Exercises (M)(H)