Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-11-1

Cybersecurity Requirements For Penetration Testing Exercises Must Be Defined, Documented And Approved.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-11-2

The Cybersecurity Requirements For Penetration Testing Processes Must Be Implemented.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-11-3

  1. The cybersecurity requirements for penetration testing processes must include at least the following:
    1. Scope of penetration tests which must cover Internet-facing services and its technical components including infrastructure, websites, web applications, mobile apps, email and remote access.
    2. Conducting penetration tests periodically.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-11-4

Cybersecurity Requirements For Penetration Testing Processes Must Be Reviewed Periodically.