Cybersecurity vulnerability assessments are performed by parties that are independent of the operations of the function
Context and Guidance: In addition to vulnerability assessments that are conducted internally, the organisation should periodically have external parties conduct assessments in order to obtain a completely objective perspective. The assessors should be external to the function’s operations but not necessarily external to the organisation.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THREAT-1c, THREAT-1f, THREAT-1k.