Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment
NIST SP 800-53A Rev. 5 53A-D: Penetration Testing
Uses adversarial testing to find and exploit weakness in a system under agreed rules, producing evidence that controls hold or do not under attack.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 19 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.