Perform external penetration testing at least annually and after any significant infrastructure or application upgrade or modification (such as an operating system upgrade, a sub-network added to the environment, or a web server added to the environment).
Perform external penetrationtesting at least annually and after anysignificant infrastructure or applicationupgrade or modification (such as anoperating system upgrade, a sub-networkadded to the environment, or a webserver added to the environment).