Test Security

Information

Every ISMS must ensure regular reviews of the effectiveness of security controls and policies. To guarantee the efficiency of controls against new threats and vulnerabilities, customers need to ensure that the infrastructure is protected against attacks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Verifying existing controls requires testing. AWS customers should undertake a number of test approaches:
-External Vulnerability Assessment
-External Penetration Tests
-Internal Gray/White-box Review of Applications and Platforms

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, MEDIA PROTECTION, PLANNING, PROGRAM MANAGEMENT, RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CA-3, 800-53|MP-8, 800-53|PL-5, 800-53|PM-9, 800-53|RA-2, 800-53|RA-3, 800-53|SI-12

Plugin: amazon_aws

Control ID: c4f411cb415cce9e652d0fb35035f2f35c6484ab7ff988c29f2c3d79678da80d