The organisation should perform penetration testing for publicly exposed applications and systems that process, transmit or store PII or other sensitive information, using findings from vulnerability assessments as input.
Testing should cover both network and application layers, including attempts to exploit network weaknesses, authenticated and unauthenticated application testing, removal of false positives, and manual validation of identified weaknesses and their impact.