unified

UC-VULN-02 — Test security through independent penetration exercises

Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Vulnerability & Patch Management
type
detective
category
administrative

Details

unified_id
UC-VULN-02
title
Test security through independent penetration exercises
statement
Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.
domain
Vulnerability & Patch Management
control_type
detective
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    CA-8
    coverage
    full
    relationship
    superset_of
  • framework
    pci-dss
    control_id
    PCI-Req11
    coverage
    partial
    delta
    also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms
    relationship
    intersects_with
guidance
  • source
    nist-ai-tevv-athlon
    sourceTitle
    NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
    propositionId
    NIST-TEVV-05
    propositionTitle
    Test direct and indirect prompt injection
    sourcePages
    NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
  • source
    nist-ai-tevv-athlon
    sourceTitle
    NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
    propositionId
    NIST-TEVV-06
    propositionTitle
    Test agent tool misuse and unauthorized external actions
    sourcePages
    NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing

Source

No record-specific source URL is provided.

Connections