A  frequently  asked question  to our experts during training sessions is: “Is a pentest mandatory for us to obtain the certification?”

Before addressing this question, we feel it is important to clarify several concepts. We believe that by the end of this article, you will find a more clear-cut answer.

Firstly, what is a pentest? A penetration test, in brief, is a simulation of accessing the target by identifying vulnerabilities in the system and applications and by exploiting these vulnerabilities. The keywords in this sentence are “vulnerability”, “exploit”, and “access”. The primary objective of a pentest is, first and foremost, to test the extent to which the Organisation implements its information security policies and to verify the functionality of the defense system against incoming attacks.

As is known, the ISO/IEC 27001 Information Security Management System (ISMS) and other high-level management system standards (e.g., ISO 14001, ISO 50001, etc.) are based on risk assessment. In conducting risk assessments, we must first identify the vulnerabilities and threats associated with the software, hardware, and communication assets in our asset inventory and outline the risks stemming from these. Additionally, ISO/IEC 27002 on information  security controls, which serves as a reference standard for defining and implementing controls aimed at addressing these information security risks, should also be taken into consideration. Therefore, when implementing the ISO/IEC 27001 standard, it is essential to consider other guidance standards and controls of the 27000 family.

Controls in Annex A of ISO/IEC 27001:2022, such as 5.21, 8.8, 8.16, 8.25, 8.29, include recommendations and guidance for conducting penetration tests. For instance, the guidance on implementing the control for managing technical vulnerabilities 8.8 in ISO/IEC 27002:2022 suggests considering the conduct of planned, documented, and repeatable penetration tests or vulnerability assessments by competent and authorized parties to support the identification of vulnerabilities. Similarly, the other controls mentioned above also suggest or recommend the conduct of penetration tests.

One other question that arises is whether these tests must necessarily be conducted by independent individuals or organizations.

Some control items strongly recommend that acceptance and security tests be conducted independently. In control 8.29 of ISO/IEC 27002:2022, related to security testing and acceptance during development, it states that such tests should initially be carried out by the development team for in-house purposes. Subsequently, independent acceptance tests should be conducted to ensure the system functions as expected, and only as expected.

In conclusion, yes, conducting a pentest is a requirement for a proper ISMS, and organizations with competent individuals in their information security teams may meet this requirement using their own resources. Those unable to perform a pentest with their own resources, on the other hand, should examine the TS 13638 standard and seriously consider beginning talks  with competent and independent organizations that carry out these tests.

The 10k Information Security Team