Cybersecurity vulnerability assessments are performed by parties that are independent of the operations of the function
In addition to vulnerability assessments that are conducted internally, the organization should periodically have external parties conduct assessments in order to obtain a completely objective perspective. The assessors should be external to the function’s operations but not necessarily external to the organization.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THREAT-1c, THREAT-1f, THREAT-1k.