STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← CA-2 (2) — Control Assessments

CCI-000256

Definition

Include as part of the control assessments, announced or unannounced, on an organization-defined frequency, in-depth monitoring; security instrumentation; automated security test cases; vulnerability scanning; malicious user testing; insider threat assessment; performance and load testing; data leakage or data loss assessment; and/or organization-defined other forms of assessment.

Parent Control

CA-2 (2)Control AssessmentsAssessment, Authorization, and Monitoring

Linked STIG Checks (1)

V-222624CAT IIThe ISSO must ensure active vulnerability testing is performed.Application Security and Development Security Technical Implementation Guide