CSC V7 control 19.7 – Conduct Periodic Incident Scenario Sessions for Personnel Overview CSC V7 control 19.7 recommends that organisations “Plan and conduct routine incident response exercises and scenarios for the workforce...
CSC V7 control 19.8 – Create Incident Scoring and Prioritization Schema Overview CSC V7 control 19.8 recommends that organisations “Create incident scoring and prioritization schema based on known or potential impact...
CSC V7 control 20 – Penetration Tests and Red Team Exercises Overview CSC V7 control 20 recommends that organisations “ Note CSC V7 places this control in the category of “Penetration...
CSC V7 control 20.1 – Establish a Penetration Testing Program Overview CSC V7 control 20.1 recommends that organisations “Establish a program for penetration tests that includes a full scope of...
CSC V7 control 20.2 – Conduct Regular External and Internal Penetration Tests Overview CSC V7 control 20.2 recommends that organisations “Conduct regular external and internal penetration tests to identify vulnerabilities and attack...
CSC V7 control 20.3 – Perform Periodic Red Team Exercises Overview CSC V7 control 20.3 recommends that organisations “Perform periodic Red Team exercises to test organizational readiness to identify and...
CSC V7 control 20.4 – Include Tests for Presence of Unprotected System Information and Artifacts Overview CSC V7 control 20.4 recommends that organisations “Include tests for the presence of unprotected system information and artifacts that...
CSC V7 control 20.5 – Create Test Bed for Elements Not Typically Tested in Production Overview CSC V7 control 20.5 recommends that organisations “Create a test bed that mimics a production environment for specific penetration...
CSC V7 control 20.6 – Use Vulnerability Scanning and Penetration Testing Tools in Concert Overview CSC V7 control 20.6 recommends that organisations “Use vulnerability scanning and penetration testing tools in concert. The results of...
CSC V7 control 20.7 – Ensure Results from Penetration Test are Documented Using Open, Machine-readable Standards Overview CSC V7 control 20.7 recommends that organisations “Wherever possible, ensure that Red Teams results are documented using open, machine-readable...