Below the Waterline Stage 2 - Regulating Red Teams 0 ▲ ZephrSec - Adventures In Information Security 1 hour ago · 10 min read2093 words · Politics · hide · 0 comments Part two of the less sexy side of red teaming.In part one, I wrote about the planning discipline behind a red team engagement: threat-led scoping, risk workshops, Rules of Engagement, communications, environmental tiering, accelerators and the role of the Red Team Manager. That work does not stop when delivery begins. The scope, escalation routes and risk decisions agreed during planning are what the team relies on when an unexpected opportunity appears or testing needs to pause.The obvious difference in a regulated engagement is that there is another stakeholder in the room. Sometimes the regulator is literally on the calls. More often, its presence is felt through the framework, the required deliverables and the knowledge that decisions may be examined long after the test has finished.That changes the standard of delivery in that more often than not decisions need named owners, understood risks and evidence that can be examined after the engagement ends.It is no longer enough for an… No comments yet. Log in to reply on the Fediverse. Comments will appear here.