Red Team
What is Red Team?
A group of security professionals authorised to simulate real-world attacks against an organisation to test its defences. Red team exercises are more comprehensive than penetration tests and evaluate people, processes, and technology holistically.
Terms that appear alongside red team
Each of these is named in at least one of the same controls as red team. The number is how many controls name both.
- nist 16 shared controls
- cybersecurity 13 shared controls
- penetration testing 12 shared controls
- resilience 11 shared controls
- governance 9 shared controls
- compliance 9 shared controls
- audit 9 shared controls
- vulnerability 9 shared controls
Frameworks that govern red team
What the standards actually require on red team
Requirements naming red team across 6 standards, quoted from the control text.
The red-team provider drafts a Red Team Test Report detailing the scenarios executed, the attack paths, findings and observations.
TIBER-3.1 · Red Team Test Report →Safety (Anzen 安全) is the second of 10 Principles per Japan AI Guidelines for Business + significantly extended by establishment of the Japan AI Safety Institute (AISI 日本AIセーフティ・インスティテュート) on 14 February 2024.
JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming · Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Employ technical specialists to attempt to break into the organisation's networks (red teaming) to test defences.
ASIC-CR-DE-3 · Red teaming →Conduct red team operations and penetration testing on a regular basis to simulate real-world attacks and reveal risks that vulnerability scanning does not surface.
ASBv3-PV-7 · Conduct regular red team operations →Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
CA-8(2) · Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises] →Questions people ask about red team
What is Red Team?
Why is Red Team important for compliance?
Which compliance frameworks address Red Team?
Where can I learn more about Red Team?
See how Red Team applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.