Expert Advice Community

Guest

Requirement for vulnerability scanning

  Quote
Guest
Guest user Created:   Mar 06, 2018 Last commented:   Mar 06, 2018

Requirement for vulnerability scanning

I want to verify in what part of the ISO compliance that will require a company to do 3rd party scanning for vulnerability assessment and penetration testing...
0 0

Assign topic to the user

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

Expert
Rhand Leal Mar 06, 2018

Answer: The performing of vulnerability scanning or penetration testing, either by the organization itself or by a 3rd party, are options to be considered only if the control A.18.2.3 (Technical compliance review) is considered applicable as result of risk assessment or because of a top management decision. It is important to understand that vulnerability scanning or penetration testing are only options. If other means, like manual reviews, can fulfill your needs, the performing of vulnerability scanning or penetration testing are not necessary.

This article will provide you further explanation about vulnerabilities management:
- How to use penetration testing for ISO 27001 A.12.6.1 https://advisera.com/27001academy/blog/2016/01/18/how-to-use-penetration-testing-for-iso-27001-a-12-6-1/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 06, 2018

Mar 06, 2018

Suggested Topics