20.7: Ensure Results From Penetration Test Are Documented Using Open, Machine-Readable Standards

Wherever possible, ensure that Red Team results are documented using open, machine-readable standards (e.g., SCAP). Devise a scoring method for determining the results of Red Team exercises so that results can be compared over time.

Asset Type

Security Function

Implementation Groups

N/A

N/A

3

Dependencies

  • Sub-control 20.1: Establish a Penetration Testing Program

Inputs

  1. Enterprise red team policy

  2. Latest red team result documentation

Operations

  1. Examine the enterprise red team policy for the following properties:
    1. Red team documentation is machine-readable

    2. Red team documentation is based on open specification

    3. Red team results must be scored to support ongoing comparison

  2. Examine the latest red team results documentation to verify
    1. Documentation is machine-readable

    2. Documentation is based on open specification

    3. Current score was compared to previous score

Measures

  • M1 = (Boolean) 1 if the Policy demands machine-readable red team results documentation; 0 otherwise

  • M2 = (Boolean) 1 if the Policy demands open specification for machine-readable results; 0 otherwise

  • M3 = (Boolean) 1 if the Policy demands results to be scored to support ongoing comparison; 0 otherwise

  • M4 = (Boolean) 1 if the Last red team results are machine-readable; 0 otherwise

  • M5 = (Boolean) 1 if the Last red team results are based on an open specification; 0 otherwise

  • M6 = (Boolean) 1 if the Last red team results includes current and previous score for comparison. In the event the current score is the result of the enterprise’s first red team exercise, this can be set to 1; 0 otherwise

Metrics

Policy Conformance

Metric

Is the enterprise’s Red Team policy specified to produce results using open, machine
readable standards, and is scoring designed to facilitate ongoing comparison?

Calculation

M1 AND M2 AND M3

Operational Conformance

Metric

Is the enterprise’s Red Team policy being practiced operationally?

Calculation

M4 AND M5 AND M6