Security tests verify that a control is functioning properly. These tests include *automated scans, tool-assisted penetration tests, and manual attempts* to undermine security. Security tests should take place on regular schedule, with attention paid to each of the key security controls. During review, the following factors should be taken into consideration: - Availability of security testing resources - Criticality of the systems and applications protected by the tested controls * Sensitivity of information contained on tested systems and applications. * Likelihood of a technical failure of the mechanism implementing the control * Likelihood of a misconfiguration of the control that would jeopardise security * Risk that the system will come under attack * Rate of change of the control configuration * Other changes in the technical environment that may affect the control performance * Difficulty and time required to perform a control test * Impact of the test on normal business operations After assessing each of these factors, security teams *design and validate a comprehensive assessment* and testing strategy. This strategy may include frequent automated tests supplemented by infrequent manual tests.