18.2—Perform Periodic External Penetration Tests
IG2
IG3
Network
Detect
>Control Description
Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.