|
controlCA-8
Penetration Testing (CA-8)
Conduct penetration testing [organization-defined] on [organization-defined].
Security Baselines
HIGHLOWMODERATE
assessmentauthorizationmonitoring
Why These Connect
Maps To9
These are equivalent or closely aligned requirements in other frameworks.
Baselined In1
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports5
These related controls work together — a change to one may affect the others.
Mitigates1
This control helps defend against or reduce the risk of the linked threat technique.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(5)
Threat Coverage(1 ATT&CK techniques)
Cross-Framework Mappings(9)
ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined frequency
Assignmentorganization-defined system(s) or system components