Azure Security Benchmark
Posture and Vulnerability Management

Azure Security Benchmark ASBv3-PV-7: Conduct regular red team operations

Conduct red team operations and penetration testing on a regular basis to simulate real-world attacks and reveal risks that vulnerability scanning does not surface.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.5 Perform Periodic Internal Penetration Tests

PCI DSS 4.0 · 4 controls

  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 6.4.1 6.4.1 Public web application review or automated protection

FedRAMP High · 3 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))

FedRAMP Moderate · 3 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 8.29 Security testing in development and acceptance
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 3 controls

  • 5.35 Independent review of information security
  • 8.29 Security testing in development and acceptance
  • 8.8 Management of technical vulnerabilities

NIST SP 800-172 · 3 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions

NIST SP 800-53 Rev 5 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P30 Independence and Skill of Testing Personnel

NIST SP 800-218 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CBPR-PR-33 Testing the effectiveness of safeguards
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

C5 (Germany) · 1 control

  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.15.2 Information security reviews
  • 53A-D Penetration Testing

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Posture and Vulnerability Management

You are reading one control. How much of Azure Security Benchmark have you already done?

Azure Security Benchmark ASBv3-PV-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Azure Security Benchmark your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 71 of 85 Azure Security Benchmark controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.