Skip to main content

πŸ’Ό CA-8 Penetration Testing

Description​

Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined systems or system components].

Similar​

  • Internal
    • ID: dec-c-548a7bcb

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CA-8 Penetration Testing (L)(M)(H)2
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CA-8 Penetration Testing (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.IM-01: Improvements are identified from evaluations10
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties23
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.IM-03: Improvements are identified from execution of operational processes, procedures, and activities24
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded22

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CA-8(1) Penetration Testing _ Independent Penetration Testing Agent or Team
πŸ’Ό CA-8(2) Penetration Testing _ Red Team Exercises
πŸ’Ό CA-8(3) Penetration Testing _ Facility Penetration Testing