Rules of Engagement (ROE)
Defines legal boundaries, operational constraints, and technical scope prior to security assessments.
- Permission: Explicit permission for the engagement is essential for legal protection.
- Test Scope: Specifies exact target systems (e.g., servers, applications).
- Rules: Defines permitted techniques (e.g., phishing prohibited, MITM allowed).