What to Provide
Penetration testing policy, Most recent penetration test, evidence of vulnerability remediation for critical and high findings.
The evidence should demonstrate:
How you conduct penetration testing
The process and timelines that your team will follow for remediation of any Critical or High findings
Evidence Format
Exported word processing documents in a common file type such as .docx or .pdf or screenshots or exported images in a common image file type such as .jpg, .png, or .pdf.
Additional Guidance
If you are using Thoropass' templates, your penetration test policy may be included as part of your Vulnerability Management Policy.
Associated Unified Control ID | Associated Framework Control |
CTRL-174 | LCL-20 |