Penetration Testing and Technical Security Assessments (SP 800-115)
Conduct at least annual penetration tests for:
Internet-facing systems
Business-critical applications
Post-incident or high-risk changes
Follow five-phase methodology:
Planning & Reconnaissance
Scanning & Enumeration
Vulnerability Assessment
Exploitation
Post-Assessment Reporting & Lessons Learned
Reference:
SP 800-115 https://www.nist.gov/privacy-framework/nist-sp-800-115
Last updated