Skip to content

Red Team

What is Red Team?

A group of security professionals authorised to simulate real-world attacks against an organisation to test its defences. Red team exercises are more comprehensive than penetration tests and evaluate people, processes, and technology holistically.

Information Security

Each of these is named in at least one of the same controls as red team. The number is how many controls name both.

What the standards actually require on red team

Requirements naming red team across 6 standards, quoted from the control text.

The red-team provider drafts a Red Team Test Report detailing the scenarios executed, the attack paths, findings and observations.

TIBER-3.1 · Red Team Test Report

Safety (Anzen 安全) is the second of 10 Principles per Japan AI Guidelines for Business + significantly extended by establishment of the Japan AI Safety Institute (AISI 日本AIセーフティ・インスティテュート) on 14 February 2024.

JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming · Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports

Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;

JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response

Employ technical specialists to attempt to break into the organisation's networks (red teaming) to test defences.

ASIC-CR-DE-3 · Red teaming

Conduct red team operations and penetration testing on a regular basis to simulate real-world attacks and reveal risks that vulnerability scanning does not surface.

ASBv3-PV-7 · Conduct regular red team operations
FedRAMP High1 control

Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

CA-8(2) · Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

Questions people ask about red team

What is Red Team?
A group of security professionals authorised to simulate real-world attacks against an organisation to test its defences. Red team exercises are more comprehensive than penetration tests and evaluate people, processes, and technology holistically.
Why is Red Team important for compliance?
Red Team is a key concept in Information Security. Understanding red team helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Red Team?
Red Team appears in the requirement text of ECB TIBER-EU Framework, Japan AI Guidelines, Japan FSA Cybersecurity Guidelines for Financial Institutions, ASIC Cyber Resilience Good Practices, Azure Security Benchmark. Across these standards we have identified 20 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Red Team?
Explore our compliance framework pages to see how red team applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Red Team applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.