Adversary Simulation
What is Adversary Simulation?
Security testing that emulates the tactics, techniques, and procedures of real-world threat actors to evaluate an organization's detection and response capabilities.
Frameworks that govern adversary simulation
What the standards actually require on adversary simulation
Requirements naming adversary simulation across 6 standards, quoted from the control text.
The red-team provider drafts a Red Team Test Report detailing the scenarios executed, the attack paths, findings and observations.
TIBER-3.1 · Red Team Test Report →Safety (Anzen 安全) is the second of 10 Principles per Japan AI Guidelines for Business + significantly extended by establishment of the Japan AI Safety Institute (AISI 日本AIセーフティ・インスティテュート) on 14 February 2024.
JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming · Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports →HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Employ technical specialists to attempt to break into the organisation's networks (red teaming) to test defences.
ASIC-CR-DE-3 · Red teaming →Conduct red team operations and penetration testing on a regular basis to simulate real-world attacks and reveal risks that vulnerability scanning does not surface.
ASBv3-PV-7 · Conduct regular red team operations →Questions people ask about adversary simulation
What is Adversary Simulation?
Why is Adversary Simulation important for compliance?
Which compliance frameworks address Adversary Simulation?
Where can I learn more about Adversary Simulation?
See how Adversary Simulation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.