CIS Controls v8
CIS Control 18: Penetration Testing

CIS Controls v8 CIS-18.4: Validate Security Measures

After every penetration test, validate the security measures in place, and where judged necessary change rulesets and capabilities so the techniques used in the test can be detected.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 7 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.27 Learning from information security incidents
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance
  • 8.32 Change management

ISO 27701:2019 · 5 controls

  • 5.6.2 Information security risk assessment
  • 5.7 Performance evaluation
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.8.1 Nonconformity and corrective action
  • 6.9.6 Technical vulnerability management

NIST SP 800-53 Rev 5 · 5 controls

FedRAMP High · 3 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))

FedRAMP Moderate · 3 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))

ISO/IEC 42001:2023 · 3 controls

  • 10.2 Nonconformity and corrective action
  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.4 AI system verification and validation
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

PCI DSS 4.0 · 3 controls

  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 11.4.6 11.4.6 Service provider segmentation testing every six months

CMMC 2.0 · 2 controls

ISO 22301:2019 · 2 controls

  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.2 Internal audit

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.14.7e Verify Correctness of Security Functions

APRA CPS 234 · 1 control

  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • ISM-1636 Security assessment by organisational or IRAP assessors

C5 (Germany) · 1 control

  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

DORA · 1 control

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing

HIPAA Security Rule · 1 control

ISO 27002:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 18: Penetration Testing

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-18.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.