Security Assessment - Level 4
CMMC CA.4.227 - Periodically Perform Red Teaming against Organizational Assets
Requirement text: CA.4.227: Periodically perform red teaming against organizational assets in order to validate defensive capabilities. DISCUSSION FROM SOURCE: CMMC Red Teaming is a specialized type of assessment conducted against an organization’s ...
CMMC CA.4.164 - Conduct Penetration Testing
Requirement text: CA.4.164: Conduct penetration testing periodically, leveraging automated scanning tools and ad hoc tests using human experts. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171B (MODIFIED) Penetration testing is a specialized type of ...
CMMC CA.4.163 - Leverage Security Roadmap for Improvement
Requirement text: CA.4.163: Create, maintain, and leverage a security roadmap for improvement. DISCUSSION FROM SOURCE: CMMC As organizations become more mature in their cyber security operations, it is expected that an organization will create, ...