id: "CA-08(03)" title: "Facility Penetration Testing" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-08.03" priority: "P1" implementation_level: "organization" parent: "CA-08" enhancement: True


Statement

Employ a penetration testing process that includes {{ insert: param, ca-08.03_odp.01 }} {{ insert: param, ca-08.03_odp.02 }} attempts to bypass or circumvent controls associated with physical access points to the facility.

Guidance

Penetration testing of physical access points can provide information on critical vulnerabilities in the operating environments of organizational systems. Such information can be used to correct weaknesses or deficiencies in physical controls that are necessary to protect organizational systems.

Assessment Objective

the penetration testing process includes {{ insert: param, ca-08.03_odp.01 }} {{ insert: param, ca-08.03_odp.02 }} attempts to bypass or circumvent controls associated with physical access points to facility.

Assessment, authorization, and monitoring policy

procedures addressing penetration testing

procedures addressing red team exercises

assessment plan

results of red team exercises

penetration test report

assessment report

rules of engagement

assessment evidence

system security plan

privacy plan

other relevant documents or records

Organizational personnel with assessment responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

Automated mechanisms supporting the employment of red team exercises