Penetration testing: the clause the question tests
Whether an independent tester attacks the service on a cycle, and what happened to the findings.
How the customer usually asks it
example"Do you commission an independent penetration test of the service at least once a year?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 8.8 Management of technical vulnerabilities |
| SIG (Shared Assessments) | domain P Threat Management |
| PCI DSS v4.0.1 | 11.4.3 External penetration testing annually |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The latest penetration test summary (tester, date, scope, findings by severity) and the remediation status of each finding.
The clauses, with what an assessor asks for
ISO 27001 8.8 Management of technical vulnerabilitiesObtain vulnerability information, evaluate exposure, and take appropriate remediation.
Where answers usually fall short: Relying on ad-hoc scans only; Missing documented risk ranking for vulnerabilities
Source: ISO/IEC 27001:2022
SIG domain P Threat ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.
Where answers usually fall short: Critical vulnerabilities open beyond SLA; Penetration test scope omits new applications
Source: SIG (Shared Assessments)
PCI DSS 11.4.3 External penetration testing annuallyWhat it asks for, in one line (the standard's own text is not quoted here):
External penetration testing is performed at least once every 12 months and after any significant infrastructure or application upgrade or change.
Where answers usually fall short: Internal team performed external test; Findings open
Source: PCI DSS v4.0.1