Commission penetration tests at least annually by qualified internal personnel or external providers, following a documented test methodology across the components identified as relevant in a risk analysis, rating findings against defined criteria and remediating medium and high criticality findings within set time windows.
What else in your programme already covers this
This control maps to 58 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components
CA-8(2) Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components
CA-8(2) Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
You are reading one control. How much of C5 (Germany) have you already done?
C5 (Germany) C5-OPS-19 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.