Security Questionnaire Mapper

Penetration testing: the clause the question tests

Whether an independent tester attacks the service on a cycle, and what happened to the findings.

How the customer usually asks it

example

"Do you commission an independent penetration test of the service at least once a year?"

Read this question

Anchor clauses

3 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.8 Management of technical vulnerabilities
SIG (Shared Assessments)domain P Threat Management
PCI DSS v4.0.111.4.3 External penetration testing annually

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The latest penetration test summary (tester, date, scope, findings by severity) and the remediation status of each finding.

The clauses, with what an assessor asks for

ISO 27001 8.8 Management of technical vulnerabilities

Obtain vulnerability information, evaluate exposure, and take appropriate remediation.

Evidence an assessor expects: Vulnerability feed logs; Risk assessment reports; Remediation ticket records; Patch deployment evidence
Where answers usually fall short: Relying on ad-hoc scans only; Missing documented risk ranking for vulnerabilities
Source: ISO/IEC 27001:2022
SIG domain P Threat Management

What it asks for, in one line (the standard's own text is not quoted here):

Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.

Evidence an assessor expects: Threat intelligence sources and feeds; Vulnerability scan reports with remediation timelines; Annual external penetration test report; Red team or purple team exercise reports
Where answers usually fall short: Critical vulnerabilities open beyond SLA; Penetration test scope omits new applications
Source: SIG (Shared Assessments)
PCI DSS 11.4.3 External penetration testing annually

What it asks for, in one line (the standard's own text is not quoted here):

External penetration testing is performed at least once every 12 months and after any significant infrastructure or application upgrade or change.

Evidence an assessor expects: Annual external pen test report by qualified third party; Engagement letter establishing independence; Findings tracker and remediation tickets; Re-test evidence; Statement of work
Where answers usually fall short: Internal team performed external test; Findings open
Source: PCI DSS v4.0.1

Other families in operations, logging and vulnerability