Skip to content

CSF Tools

  • Home
  • Blog
  • Visualizations
  • Login
  • CIS Critical Security Controls
  • Critical Security Controls v8.1
  • 18: Penetration Testing

18.4: Validate Security Measures

Group:

  • IG3
Info icon.

Control is new to this version of the control set.

Control Statement

Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing.

[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]

Advanced Search

Related Security Visualizations

Adjacency Matrix of Controls in the Privacy Framework
Adjacency Matrix of Controls in the Privacy Framework
Sunburst Visualization of the Privacy Framework
Sunburst Visualization of the Privacy Framework
Sunburst Visualization of the Cyber Security Framework v2.0
Sunburst Visualization of the Cyber Security Framework v2.0

Frameworks and Controls

  • NIST Cybersecurity Framework
    • Cybersecurity Framework v1.1 [Summary]
    • Cybersecurity Framework v2.0 [Summary]
  • NIST Privacy Framework
    • Privacy Framework v1.0 [Summary]
  • NIST Special Publication 800-53
    • NIST SP 800-53, Revision 4 [Summary]
    • NIST SP 800-53, Revision 5.2.0 [Summary]
  • NIST Special Publication 800-82
    • NIST SP 800-82, Revision 3.0 [Summary]
  • NIST Special Publication 800-171
    • NIST SP 800-171, Revision 2 [Summary]
    • NIST SP 800-171, Revision 3.0 [Summary]
  • CSA Cloud Controls Matrix
    • Cloud Controls Matrix v3.0.1 [Summary]
    • Cloud Controls Matrix Version 4.0 [Summary]
  • CIS Critical Security Controls
    • Critical Security Controls v7.1 [Summary]
    • Critical Security Controls v8.1 [Summary]
      • 1: Inventory and Control of Enterprise Assets
      • 2: Inventory and Control of Software Assets
      • 3: Data Protection
      • 4: Secure Configuration of Enterprise Assets and Software
      • 5: Account Management
      • 6: Access Control Management
      • 7: Continuous Vulnerability Management
      • 8: Audit Log Management
      • 9: Email and Web Browser Protections
      • 10: Malware Defenses
      • 11: Data Recovery
      • 12: Network Infrastructure Management
      • 13: Network Monitoring and Defense
      • 14: Security Awareness and Skills Training
      • 15: Service Provider Management
      • 16: Application Software Security
      • 17: Incident Response Management
      • 18: Penetration Testing
        • 18.1: Establish and Maintain a Penetration Testing Program
        • 18.2: Perform Periodic External Penetration Tests
        • 18.3: Remediate Penetration Test Findings
        • 18.4: Validate Security Measures
        • 18.5: Perform Periodic Internal Penetration Tests
  • STRIDE-LM Threat Model
  • Home
  • Blog
  • Visualizations
  • Privacy Policy
  • Disclaimer
© 2026 CSF Tools