web analytics

Cyber Security – Red Team

Rules of Engagements

Section NameSection Details
Executive SummaryOverarching summary of all contents and authorization within RoE document
PurposeDefines why the RoE document is used
ReferencesAny references used throughout the RoE document (HIPAA, ISO, etc.)
ScopeStatement of the agreement to restrictions and guidelines
DefinitionsDefinitions of technical terms used throughout the RoE document
Rules of Engagement and Support AgreementDefines obligations of both parties and general technical expectations of engagement conduct
ProvisionsDefine exceptions and additional information from the Rules of Engagement
Requirements, Restrictions, and Authority Define specific expectations of the red team cell
Ground RulesDefine limitations of the red team cell’s interactions
Resolution of Issues/Points of ContactContains all essential personnel involved in an engagement
AuthorizationStatement of authorization for the engagement
Approval Signatures from both parties approving all subsections of the preceding document
AppendixAny further information from preceding subsections

Campaign Planning

Type of PlanExplanation of PlanPlan Contents
Engagement PlanAn overarching description of technical requirements of the red team.CONOPS, Resource and Personnel Requirements, Timelines
Operations PlanAn expansion of the Engagement Plan. Goes further into specifics of each detail.Operators, Known Information, Responsibilities, etc.
Mission PlanThe exact commands to run and execution time of the engagement.Commands to run, Time Objectives, Responsible Operator, etc.
Remediation PlanDefines how the engagement will proceed after the campaign is finished.Report, Remediation consultation, etc.

Engagement Plan:

ComponentPurpose
CONOPS (Concept of Operations)Non-technically written overview of how the red team meets client objectives and target the client.
Resource planIncludes timelines and information required for the red team to be successful—any resource requirements: personnel, hardware, cloud requirements.

Operations Plan:

ComponentPurpose
Personnel Information on employee requirements.
Stopping conditionsHow and why should the red team stop during the engagement.
RoE (optional)
Technical requirementsWhat knowledge will the red team need to be successful.

Mission Plan:

ComponentPurpose
Command playbooks (optional)Exact commands and tools to run, including when, why, and how. Commonly seen in larger teams with many operators at varying skill levels.
Execution timesTimes to begin stages of engagement. Can optionally include exact times to execute tools and commands.
Responsibilities/rolesWho does what, when.

Remediation Plan (optional):

ComponentPurpose
ReportSummary of engagement details and report of findings.
Remediation/consultation How will the client remediate findings? It can be included in the report or discussed in a meeting between the client and the red team.

The Concept of Operation (CONOPS) is a part of the engagement plan that details a high-level overview of the proceedings of an engagement; we can compare this to an executive summary of a penetration test report. The document will serve as a business/client reference and a reference for the red cell to build off of and extend to further campaign plans.

The CONOPS document should be written from a semi-technical summary perspective, assuming the target audience/reader has zero to minimal technical knowledge.