While reviewing your policies to see how you handled Vanta templates with the requirement for yearly penetrations tests, I noticed you removed this from the Operations Security Policy. Was it your intention to keep the yearly requirement for a penetration test in your Risk Management Policy? If this was an oversight, I wanted to draw your attention to it.
Risks are assessed and ranked according to their impact and their likelihood of occurrence. A formal Risk Assessment, and network penetration tests, will be performed at least annually and shall take into consideration the results of any technical vulnerability management activities performed in accordance with the Operations Security Policy.
Pay now to fund the work behind this issue.
Get updates on progress being made.
Maintainer is rewarded once the issue is completed.
You're funding impactful open source efforts
You want to contribute to this effort
You want to get funding like this too