Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
CORE IMPACT Pro
Penetration Testing Software
SHARE

CORE IMPACT Pro Penetration Testing Reports: 
FISMA Vulnerability Validation Report


Testing Vectors:
Network Systems

The FISMA Report provides results of penetration testing performed by government entities and other organizations working to remain compliant with the Federal Information Security Management Act of 2002 (FISMA), enacted by Congress to require each federal agency to “develop, document, and implement an agency-wide program to provide information security” for sensitive data. The report specifically highlights that organizations have met penetration testing requirements outlined in Special Document 800-53a (Appendix G) published by the National Institute of Standards and Technology (NIST), as well as in the Consensus Audit Guidelines issued by a number of constituents including NIST and federal agencies such as the DoD and DHS.

Targeted Report Results:

  • Penetration testing results: proves the ongoing adoption of various FISMA/NIST/CAG controls including required pen testing assessment and Red Team exercises.
  • Summaries of exploited vulnerabilities: Maps exploitable vulnerabilities identified by IMPACT to the FISMA/NIST/CAG controls these vulnerabilities would violate.
  • Detailed exploit descriptions: Helps identify how other FISMA/NIST/CAG-required defensive controls are working and should be strengthened.

Takeaways:

  • Extensive lists of vulnerabilities validated and tested with status information regarding their location, availability and related risk, as well as logging of required assessments.
  • Detailed results regarding how an organization is working to meet both the requirements and underlying spirit of multiple government security standards.
Related Content



Learn more about penetration testing, the approach used by CORE IMPACT security testing software solutions.

Additional Reporting Features

CORE IMPACT Pro reports offer the following additional features for meeting your unique assessment goals:

SCAP Support
In support of the SCAP standard, CORE IMPACT Pro incorporates CVE, CVSS and CPE data into the product's reports and can also export this data in XML format for use in centralized security databases.

Customization
Many CORE IMPACT Pro reports can be tailored to meet the needs of different internal constituencies by providing tailored results for groups including IT management, network administrators, remediation staff, and other IT/security professionals. Additionally, the reports are exportable to other applications for integration with complimentary sets of data.

Aggregation
CORE IMPACT Pro report consolidation capabilities enable customers to create overarching reports of enterprise penetration testing results. Users can import and consolidate results from different penetration tests - conducted at various times using multiple workspaces and consoles - into each of IMPACT Pro’s standard report templates.