workflow

Technical Security Testing & Pentest Engagement

Runs ON an existing Audit item (audit_type: it_audit) that represents the authorized penetration-test engagement — the workflow instance attaches to that record and enriches it (scope, ratings, dates, and the assurance conclusion write back to its fields); it never creates a duplicate engagement record. In scope: authorized technical testing (reconnaissance, discovery, exploitation validation, severity rating, reporting, and retest) of the defined system boundary against its control baseline and assessment objective, with each confirmed finding recorded as an Issue linked to the anchor Audit and its affected Controls. Out of scope: any testing beyond the agreed rules of engagement, and the downstream remediation program itself — confirmed control gaps and open POA&M findings are handed to the Security Control Assessment & POA&M Remediation workflow, and the assurance conclusion to the Cybersecurity Assurance Review workflow. No upstream workflow feeds this engagement; its inputs are the anchor Audit, the in-scope system boundary (Process items), the control baseline (Control items, framework nist-800-53), the assessment objective and signed authorization, and any open Issue items (source: penetration_test / vulnerability_scan) from prior engagements.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
assure

Details

teams
  • it
domains
  • controls
standards
  • nist-800-53
sourceTemplateId
workflow-library:controls-technical-security-testing-pentest
releaseId
sha256:c28fb0e08623dc507cf60fcdf8730d6f0b13de3d95018f9692f7c72965a24317
canonicalUrl
https://workflow-library.com/all/?w=controls-technical-security-testing-pentest
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-VULN-02
    • UC-SDLC-14
    • UC-SDLC-04
    • UC-CONFIG-04
    • UC-NET-01
    • UC-NET-02
    • UC-NET-03
    • UC-NET-04
    • UC-SDLC-05
    • UC-VULN-04
    • UC-VULN-07
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:c28fb0e08623dc507cf60fcdf8730d6f0b13de3d95018f9692f7c72965a24317

            Connections