workflow
Technical Security Testing & Pentest Engagement
Runs ON an existing Audit item (audit_type: it_audit) that represents the authorized penetration-test engagement — the workflow instance attaches to that record and enriches it (scope, ratings, dates, and the assurance conclusion write back to its fields); it never creates a duplicate engagement record. In scope: authorized technical testing (reconnaissance, discovery, exploitation validation, severity rating, reporting, and retest) of the defined system boundary against its control baseline and assessment objective, with each confirmed finding recorded as an Issue linked to the anchor Audit and its affected Controls. Out of scope: any testing beyond the agreed rules of engagement, and the downstream remediation program itself — confirmed control gaps and open POA&M findings are handed to the Security Control Assessment & POA&M Remediation workflow, and the assurance conclusion to the Cybersecurity Assurance Review workflow. No upstream workflow feeds this engagement; its inputs are the anchor Audit, the in-scope system boundary (Process items), the control baseline (Control items, framework nist-800-53), the assessment objective and signed authorization, and any open Issue items (source: penetration_test / vulnerability_scan) from prior engagements.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- assure
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- sourceTemplateId
- workflow-library:controls-technical-security-testing-pentest
- releaseId
- sha256:c28fb0e08623dc507cf60fcdf8730d6f0b13de3d95018f9692f7c72965a24317
- canonicalUrl
- https://workflow-library.com/all/?w=controls-technical-security-testing-pentest
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-VULN-02
- UC-SDLC-14
- UC-SDLC-04
- UC-CONFIG-04
- UC-NET-01
- UC-NET-02
- UC-NET-03
- UC-NET-04
- UC-SDLC-05
- UC-VULN-04
- UC-VULN-07
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:c28fb0e08623dc507cf60fcdf8730d6f0b13de3d95018f9692f7c72965a24317
Connections
- Technical Security Testing & Pentest Engagement tests UC-SDLC-04 — Engineer systems with secure architecture and design
- Technical Security Testing & Pentest Engagement tests UC-NET-01 — Segment networks and defend the external boundary
- Technical Security Testing & Pentest Engagement tests UC-NET-02 — Authorize and secure remote, wireless, and mobile access
- Technical Security Testing & Pentest Engagement tests UC-NET-03 — Provide trusted channels and control session lifecycle
- Technical Security Testing & Pentest Engagement tests UC-CONFIG-04 — Build security and privacy into software design and upkeep
- Technical Security Testing & Pentest Engagement tests UC-VULN-07 — Harden runtime error handling, output filtering, and memory
- Technical Security Testing & Pentest Engagement operates UC-VULN-02 — Test security through independent penetration exercises
- Technical Security Testing & Pentest Engagement tests UC-VULN-04 — Test software security during development and acceptance
- Technical Security Testing & Pentest Engagement operates UC-SDLC-14 — Protect production systems during audit testing
- Technical Security Testing & Pentest Engagement tests UC-SDLC-05 — Enforce secure coding and input validation standards
- Technical Security Testing & Pentest Engagement tests UC-NET-04 — Isolate system, user, and security functions