Rules of Engagement (ROE)

Defines legal boundaries, operational constraints, and technical scope prior to security assessments.

  • Permission: Explicit permission for the engagement is essential for legal protection.
  • Test Scope: Specifies exact target systems (e.g., servers, applications).
  • Rules: Defines permitted techniques (e.g., phishing prohibited, MITM allowed).