9:010-AP8 Penetration Testing & Security Assessment Procedure
9:010-AP8 Penetration Testing & Security Assessment Procedure
Purpose
This administrative procedure establishes a controlled and authorized process for identifying and addressing technical vulnerabilities in District systems while protecting District operations, privacy, and confidential information.
Scope
This procedure applies to penetration testing and related security assessments of District networks, systems, applications, cloud services, and other technology environments that support District operations or contain confidential information.
It also applies to District-directed testing of vendor-hosted systems when the District has authorization to conduct such testing.
Responsibilities
Technology Director – Authorizes testing, approves the scope, and oversees the District’s response to identified risks.
Technology Department – Coordinates testing, reviews findings, and tracks corrective action.
Third-Party Testing Provider – Conducts authorized testing according to the approved scope and protects District systems, information, and findings.
Procedure
I. Assessment Program
The District will conduct an independent penetration test at least annually. The scope will be based on current risks, significant technology changes, previous findings, and the importance of the systems being assessed.
The assessment may include external and internal networks, applications, cloud services, identity and access controls, wireless systems, and other technology assets selected based on risk.
Routine vulnerability scanning does not, by itself, satisfy the requirement for an independent penetration test.
Additional testing or security assessments may be conducted following a significant system change, cybersecurity incident, material vendor change, or other identified risk.
II. Authorization and Testing
Testing will be conducted by an authorized provider according to a written scope and established Rules of Engagement.
Testing of vendor-hosted or other third-party systems will only be conducted when the District has written authorization or contractual authority to do so.
Testing will use recognized cybersecurity practices and will be planned and conducted to protect District information and minimize disruption to instruction and District operations.
III. Findings and Remediation
Testing results will be reviewed and prioritized based on risk. Confirmed findings will be assigned for corrective action and tracked through completion or other documented resolution.
Critical and High findings will be addressed as soon as practical. When immediate remediation is unavailable, appropriate mitigation or compensating controls will be implemented.
Material remediation will be verified through retesting or other appropriate evidence.
IV. Vendor and Cloud Assessments
When direct testing is unavailable or not permitted, the District may use independent security reports, configuration assessments, certifications, vulnerability information, or other available documentation to evaluate security controls.
Vendor assistance may be required when findings involve vendor-controlled systems, configurations, or services.
V. Records and Confidentiality
Testing authorization, reports, technical findings, evidence, and remediation records will be access-controlled and treated as confidential security information.
Records will be retained according to District requirements. Requests for public disclosure will be referred to the District’s Freedom of Information Officer for review under applicable law and District policy.
Review Cycle
The Technology Director will review this procedure annually and following a significant cybersecurity incident or material change in law, risk, District technology, or assessment requirements.
Cross References
Purpose
This administrative procedure establishes a controlled and authorized process for identifying and addressing technical vulnerabilities in District systems while protecting District operations, privacy, and confidential information.
Scope
This procedure applies to penetration testing and related security assessments of District networks, systems, applications, cloud services, and other technology environments that support District operations or contain confidential information.
It also applies to District-directed testing of vendor-hosted systems when the District has authorization to conduct such testing.
Responsibilities
Technology Director – Authorizes testing, approves the scope, and oversees the District’s response to identified risks.
Technology Department – Coordinates testing, reviews findings, and tracks corrective action.
Third-Party Testing Provider – Conducts authorized testing according to the approved scope and protects District systems, information, and findings.
Procedure
I. Assessment Program
The District will conduct an independent penetration test at least annually. The scope will be based on current risks, significant technology changes, previous findings, and the importance of the systems being assessed.
The assessment may include external and internal networks, applications, cloud services, identity and access controls, wireless systems, and other technology assets selected based on risk.
Routine vulnerability scanning does not, by itself, satisfy the requirement for an independent penetration test.
Additional testing or security assessments may be conducted following a significant system change, cybersecurity incident, material vendor change, or other identified risk.
II. Authorization and Testing
Testing will be conducted by an authorized provider according to a written scope and established Rules of Engagement.
Testing of vendor-hosted or other third-party systems will only be conducted when the District has written authorization or contractual authority to do so.
Testing will use recognized cybersecurity practices and will be planned and conducted to protect District information and minimize disruption to instruction and District operations.
III. Findings and Remediation
Testing results will be reviewed and prioritized based on risk. Confirmed findings will be assigned for corrective action and tracked through completion or other documented resolution.
Critical and High findings will be addressed as soon as practical. When immediate remediation is unavailable, appropriate mitigation or compensating controls will be implemented.
Material remediation will be verified through retesting or other appropriate evidence.
IV. Vendor and Cloud Assessments
When direct testing is unavailable or not permitted, the District may use independent security reports, configuration assessments, certifications, vulnerability information, or other available documentation to evaluate security controls.
Vendor assistance may be required when findings involve vendor-controlled systems, configurations, or services.
V. Records and Confidentiality
Testing authorization, reports, technical findings, evidence, and remediation records will be access-controlled and treated as confidential security information.
Records will be retained according to District requirements. Requests for public disclosure will be referred to the District’s Freedom of Information Officer for review under applicable law and District policy.
Review Cycle
The Technology Director will review this procedure annually and following a significant cybersecurity incident or material change in law, risk, District technology, or assessment requirements.
