PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CA-8 — Penetration Testing

Framework: NIST SP 800-53 Rev.5 CA-8 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Obtain the penetration testing plan or policy and confirm it defines the testing frequency, the in-scope systems and components, the testing methodology, and documented rules of engagement.
Examine Review the most recent penetration test report to confirm testing was actually performed at the organization-defined frequency and covered the defined target systems, aligning with CIS Controls v8 Control 18 (Penetration Testing).
Examine Verify that authorized rules of engagement (scope, timing, permitted techniques, and management sign-off) were documented and approved before the test commenced.
Interview Interview the penetration test coordinator or team to confirm the testers were independent of the system's development and operations staff and possessed the required skills (per CA-8(1)).
Examine Confirm every exploitable finding from the penetration test was entered into the POA&M or tracking system with a severity rating, remediation owner, and target date.
Test For a sample of penetration-test findings marked remediated, obtain retest/validation evidence or re-observe the condition to confirm the vulnerability is no longer exploitable.
Examine Where red team exercises or specialized assessments are required (per CA-8(2)), confirm they were conducted with documented objectives, scope, and results feeding the risk and remediation process.