Frameworks / NIST SP 800-53 Rev 5 / NIST800-CA-8 NIST SP 800-53 Rev 5
CA - Assessment, Authorization, and Monitoring
NIST SP 800-53 Rev 5 NIST800-CA-8: CA-8 Penetration Testing Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined systems or system components].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 114 controls across 59 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
11.4.1 11.4.1 Penetration testing methodology defined and implemented 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.3 11.4.3 External penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.4.5 11.4.5 Annual segmentation penetration testing 11.4.6 11.4.6 Service provider segmentation testing every six months 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 6.2.3 6.2.3 Code review before release 6.4.1 6.4.1 Public web application review or automated protection CIS-16.13 Conduct Application Penetration Testing CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-18.5 Perform Periodic Internal Penetration Tests 5.35 Independent review of information security 8.29 Security testing in development and acceptance 8.34 Protection of information systems during audit testing 8.8 Management of technical vulnerabilities CA-8 Penetration Testing CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2)) CA-8 Penetration Testing CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2)) 5.35 Independent review of information security 8.29 Security testing in development and acceptance 8.34 Protection of information systems during audit testing 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring PTESPHASE-4 Vulnerability Analysis PTES-1.1 Define and record the scope in writing before testing PTES-3.4 Ensure exploitation and confirmation stay authorised, planned and least-disruptive CISABD-2 Embrace Radical Transparency and Accountability CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes SBD-DEV-07 Dependency Management and SBOM ASBv3-DS-5 Integrate dynamic application security testing into DevOps pipeline ASBv3-PV-7 Conduct regular red team operations DORA-Art.25 Testing of ICT tools and systems DORA-Art.26 Advanced testing of ICT tools, systems and processes based on TLPT 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program BSI-14 Vulnerability scanning and management C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests CPG-5.A Vulnerability Disclosure Program TIBER-2.3 Active red team testing on live production CAT-D3-3 Corrective controls FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) 27011-8.5 Vulnerability and malware management ISO27043-25 Technical vulnerability management 29134-9.2 Report findings and recommendations ISO21434-25 Technical vulnerability management NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) 3.12.1e Penetration Testing by Independent Agents CA-8 CA-8 Penetration Testing 53A-D Penetration Testing NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning RMI-DD-4 Due Diligence Reporting SAEIGHT-1 Child Labour and Young Worker Protection SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SSAE18-CC7.4 CC7.4 - Incident Response SOCI-S30CU Vulnerability assessments SCA-S26 Licensing Framework IM8-SEC.4 Vulnerability Management ISMSP-SYS-04 Vulnerability Management TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator UKOPRES-4 Incident Management, Lessons Learned, Comms VES-3 Penetration Testing Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CA - Assessment, Authorization, and Monitoring You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-CA-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 114 it maps to, and the evidence behind each claim, over MCP and REST.