unified
UC-VULN-02 — Test security through independent penetration exercises
Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Vulnerability & Patch Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-VULN-02
- title
- Test security through independent penetration exercises
- statement
- Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.
- domain
- Vulnerability & Patch Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CA-8
- coverage
- full
- relationship
- superset_of
- framework
- pci-dss
- control_id
- PCI-Req11
- coverage
- partial
- delta
- also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms
- relationship
- intersects_with
- guidance
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-05
- propositionTitle
- Test direct and indirect prompt injection
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-06
- propositionTitle
- Test agent tool misuse and unauthorized external actions
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing
Source
No record-specific source URL is provided.
Connections
- UC-VULN-02 — Test security through independent penetration exercises mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Independent penetration testing is the operative defense against the absence of pen testing, validating exploitability.
- UC-VULN-02 — Test security through independent penetration exercises maps_to PCI-Req11 — Test security of systems and networks regularly
- framework
- pci-dss
- control_id
- PCI-Req11
- coverage
- partial
- delta
- also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-02 — Test security through independent penetration exercises informed_by NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing
- UC-VULN-02 — Test security through independent penetration exercises informed_by NIST-TEVV-05 — Test direct and indirect prompt injection
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-05
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
- UC-VULN-02 — Test security through independent penetration exercises maps_to CA-8 — Penetration Testing
- framework
- nist-800-53
- control_id
- CA-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-02 — Test security through independent penetration exercises mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Pen tests find and validate exploitable unpatched flaws and track corrective actions to verified closure.
- Technical Security Testing & Pentest Engagement operates UC-VULN-02 — Test security through independent penetration exercises
- UC-VULN-02 — Test security through independent penetration exercises mitigates Vulnerabilities introduced during software development
- strength
- related
- rationale
- Application penetration testing uncovers exploitable software vulnerabilities in built systems.
- UC-VULN-02 — Test security through independent penetration exercises mitigates Internet-exposed or misconfigured systems
- strength
- related
- rationale
- External-perspective testing directly probes and discovers internet-exposed and misconfigured systems.