CA-08.1 ยท Independent Penetration Testing Agent or Team

Control Description

Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Assurance
Enhancement
Control Statement
The control requirements

Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.

Supplemental Guidance

Independent penetration testing agents or teams are individuals or groups who conduct impartial penetration testing of organizational systems. Impartiality implies that penetration testing agents or teams are free from perceived or actual conflicts of interest with respect to the development, operation, or management of the systems that are the targets of the penetration testing. [CA-2(1)](#ca-2.1) provides additional information on independent assessments that can be applied to penetration testing.

Related NIST Controls
Other NIST 800-53 controls related to this one