CORE IMPACT Pro Penetration Testing Reports:
FISMA Vulnerability Validation Report
Testing Vectors: Network Systems
The FISMA Report provides results of penetration testing performed by government entities and other organizations working to remain compliant with the Federal Information Security Management Act of 2002 (FISMA), enacted by Congress to require each federal agency to “develop, document, and implement an agency-wide program to provide information security” for sensitive data. The report specifically highlights that organizations have met penetration testing requirements outlined in Special Document 800-53a (Appendix G) published by the National Institute of Standards and Technology (NIST), as well as in the Consensus Audit Guidelines issued by a number of constituents including NIST and federal agencies such as the DoD and DHS.
Targeted Report Results:
- Penetration testing results: proves the ongoing adoption of various FISMA/NIST/CAG controls including required pen testing assessment and Red Team exercises.
- Summaries of exploited vulnerabilities: Maps exploitable vulnerabilities identified by IMPACT to the FISMA/NIST/CAG controls these vulnerabilities would violate.
- Detailed exploit descriptions: Helps identify how other FISMA/NIST/CAG-required defensive controls are working and should be strengthened.
Takeaways:
- Extensive lists of vulnerabilities validated and tested with status information regarding their location, availability and related risk, as well as logging of required assessments.
- Detailed results regarding how an organization is working to meet both the requirements and underlying spirit of multiple government security standards.











