Yes, penetration testing is considered an important aspect of the information security management system (ISMS) specified in ISO 27001. The standard requires organizations to regularly assess the security of their systems and networks, and penetration testing is one of the recommended methods for doing so.
ISO 27001 requires organizations to implement and maintain a risk management process, and penetration testing is used to identify and evaluate potential risks to the confidentiality, integrity, and availability of information. The results of penetration testing can then be used to inform risk management decisions and to improve the overall security of the organization’s ISMS.
It is important to note that ISO 27001 does not specify how often penetration testing should be performed, or the specific methods that should be used. Rather, it leaves these decisions to the discretion of the organization and its risk management process. However, it does require that organizations regularly review and assess the effectiveness of their ISMS, including the results of penetration testing, and make changes as necessary to improve security.