CA-8: Penetration Testing

NIST Baseline:  Low 

DIR Required By:  07/20/2023 

Review Date:  09/01/2026

  • Information resource owners, in coordination with Tarleton’s Office of Innovative Technology Solutions (OITS) Security Team, are responsible for ensuring that penetration testing is completed, based on risk management decisions.  
  • Penetration testing should be conducted on a reoccurring basis on Internet websites and/or mobile applications that are exposed to the public internet that process or store sensitive, personally identifiable information (PII), or confidential information as required by Texas Government Code §2054.516(a)(2)

References/Additional Resources

Tex. Gov’t Code Section 2054.516(a)(2)