{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-02","description":"Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.","details":{"control_category":"administrative","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[{"propositionId":"NIST-TEVV-05","propositionTitle":"Test direct and indirect prompt injection","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"},{"propositionId":"NIST-TEVV-06","propositionTitle":"Test agent tool misuse and unauthorized external actions","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"CA-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PCI-Req11","coverage":"partial","delta":"also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.","title":"Test security through independent penetration exercises","unified_id":"UC-VULN-02"},"id":"uc:UC-VULN-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-02","sourceIds":["nist-800-53","nist-ai-tevv-athlon","pci-dss"],"sourceUrl":null,"title":"UC-VULN-02 — Test security through independent penetration exercises","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:29034087236d0f306681d6531032b1127a372bbe15c8f916be173d3d3292ff1d","properties":{"rationale":"Independent penetration testing is the operative defense against the absence of pen testing, validating exploitability.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:371713ad7bcf1d0ad6654e3d9c27a8204a0ecedb98b6b08e53ca86bb0aaaa12d","properties":{"control_id":"PCI-Req11","coverage":"partial","delta":"also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req11-ee0fcd89.json","targetId":"ctrl:pci-dss:PCI-Req11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f3f7bb79607aa821f7ec9d464c1eab2b0d790a7ed2ce1169b16a35f23df9fbe","properties":{"control_id":"NIST-TEVV-06","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:557c82a7744248c53a3ab7a2d104035ab2b99d4662594126609241c528da791f","properties":{"control_id":"NIST-TEVV-05","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d0ab7dad539ee79842c33f9966a097879c272387bd0aaee9256013bcc6d95b7","properties":{"control_id":"CA-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-8-bbc6c82f.json","targetId":"ctrl:nist-800-53:CA-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83346bb04be0f35ed2436f074ad8d5a47d566991b1dd22072527a6cbc5841a57","properties":{"rationale":"Pen tests find and validate exploitable unpatched flaws and track corrective actions to verified closure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98964559bf025c94d81c0fdd464402a6ec07151a97dd2f119659938a49109d2a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","targetId":"uc:UC-VULN-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e8713eaa01ce3c2f5711b923ec55bf65142a4dd30de55b8fb9bd1c1cb99ac90a","properties":{"rationale":"Application penetration testing uncovers exploitable software vulnerabilities in built systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd93e502fdfb4e7f9ef0a6fc557d02f6b10e37e080f75bef72d5722fcaa80939","properties":{"rationale":"External-perspective testing directly probes and discovers internet-exposed and misconfigured systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"}],"schemaVersion":1}
