- How often
- At least once every 12 months, and after any significant infrastructure or application upgrade or change. Segmentation controls carry their own interval at 11.4.5, and service providers a further one at 11.4.6.
- Who performs it
- A qualified internal resource or a qualified external third party, with organisational independence of the tester, working to the methodology 11.4.1 obliges you to define, document and implement.
- What it leaves behind
- Findings against that methodology, a documented approach to the risk each exploitable weakness poses, and results retained alongside the remediation record for at least 12 months.