# SP-035 Offensive Security Testing

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: Governance and execution pattern for red teaming, blue teaming, purple teaming, and intelligence-led penetration testing (CBEST, TIBER-EU). Covers threat intelligence-led scoping, controlled attack simulation, detection validation, and continuous improvement.
Use when: This pattern is relevant for any organisation that wants evidence-based assurance of its security controls. It is essential for: financial services organisations subject to CBEST, TIBER-EU, or equivalent regulatory testing requirements, critical national infrastructure operators, organisations handling sensitive personal or financial data, entities that have suffered breaches and need to validate remediation...
Not when: Organisations without basic security controls in place (no patching, no access control, no monitoring) will get limited value from offensive testing -- the findings will be obvious and overwhelming.

## Controls (29, NIST SP 800-53 ids)
- Critical (8): CA-02, CA-07, CA-08, IR-03, PM-14, PM-16, RA-03, RA-05
- Important (18): AC-01, AC-06, AT-02, AT-03, AU-02, AU-06, CA-05, CM-06, IR-04, PL-04, PM-04, PM-09, PS-06, PS-07, RA-07, SA-11, SC-07, SI-04
- Standard (3): CM-04, SA-09, SA-15

## What each critical control mitigates (8)
- CA-02 Control Assessments: T-OST-001, T-OST-006
- CA-07 Continuous Monitoring: T-OST-002, T-OST-006, T-OST-007
- CA-08 Penetration Testing: T-OST-001, T-OST-002, T-OST-003, T-OST-004, T-OST-005, T-OST-006, T-OST-008, T-OST-009, T-OST-010
- IR-03 Incident Response Testing: T-OST-005
- PM-14 Testing, Training, and Monitoring: T-OST-002, T-OST-004, T-OST-005, T-OST-006, T-OST-007
- PM-16 Threat Awareness Program: none of the threats below
- RA-03 Risk Assessment: T-OST-008
- RA-05 Vulnerability Monitoring and Scanning: T-OST-001, T-OST-003, T-OST-007

## Threats and the controls that mitigate them (10)
- T-OST-001 Undetected vulnerabilities in internet-facing systems: CA-08, RA-05, CA-02
- T-OST-002 Security controls that fail to detect real attack techniques: CA-08, CA-07, SI-04, PM-14
- T-OST-003 Lateral movement paths through Active Directory misconfigurations: CA-08, RA-05, CM-06, AC-06
- T-OST-004 Social engineering susceptibility across the workforce: CA-08, AT-02, AT-03, PM-14
- T-OST-005 Incident response process failures under realistic pressure: IR-03, IR-04, CA-08, PM-14
- T-OST-006 Compliance without actual security effectiveness: CA-02, CA-08, PM-14, CA-07
- T-OST-007 Configuration drift degrading previously effective controls: CA-07, CM-06, RA-05, PM-14
- T-OST-008 Supply chain compromise through trusted vendor access: CA-08, PS-07, SA-09, RA-03
- T-OST-009 Privilege escalation from standard user to domain administrator: CA-08, AC-06, CM-06, AU-06
- T-OST-010 Data exfiltration through unmonitored channels: CA-08, SI-04, AU-06, SC-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-035/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-035/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 29 KB: /api/v1/patterns/SP-035
- Page for people: /patterns/sp-035/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-025 Advanced Monitoring and Detection; SP-028 Secure DevOps Pipeline; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-034 Cyber Resilience

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
