Skip to main content

💼 CA-8 Penetration Testing

  • ID: /frameworks/nist-sp-800-53-r5/ca/08

Description​

Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined systems or system components].

Similar​

  • Internal
    • ID: dec-c-548a7bcb

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP High Security Controls → 💼 CA-8 Penetration Testing (L)(M)(H)2no data
💼 FedRAMP Low Security Controls → 💼 CA-8 Penetration Testing (L)(M)(H)no data
💼 NIST CSF v2.0 → 💼 ID.IM-01: Improvements are identified from evaluations26no data
💼 NIST CSF v2.0 → 💼 ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties40no data
💼 NIST CSF v2.0 → 💼 ID.IM-03: Improvements are identified from execution of operational processes, procedures, and activities41no data
💼 NIST CSF v2.0 → 💼 ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded31no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CA-8(1) Penetration Testing _ Independent Penetration Testing Agent or Teamno data
💼 CA-8(2) Penetration Testing _ Red Team Exercisesno data
💼 CA-8(3) Penetration Testing _ Facility Penetration Testingno data