Control Objectives: Applications/Network
No control objectives match the current filters.
Create Test Bed for Elements Not Typically Tested in Production
SNow
Classification: DetectState: Published
Create a test bed that mimics a production environment for specific penetration tests and Red Team attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems.
Ensure Results from Penetration Test are Documented Using Open, Machine-readable Standards
SNow
Classification: DetectState: Published
Wherever possible, ensure that Red Teams results are documented using open, machine-readable standards (e.g., SCAP). Devise a scoring method for determining the results of Red Team exercises so that results can be compared over time.
Use Vulnerability Scanning and Penetration Testing Tools in Concert
SNow
Classification: DetectState: Published
Use vulnerability scanning and penetration testing tools in concert. The results of vulnerability scanning assessments should be used as a starting point to guide and focus penetration testing efforts.