Rules of Engagement (RoE)
Definition
The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop criteria for a penetration test. Without a valid RoE, a penetration test may constitute unauthorised computer access under applicable law.
- Also known as
- Pre-test agreement
- Defines
- Scope, techniques, exclusions, test window
- Also includes
- Escalation contacts, emergency stop criteria
- Legal significance
- Absence may make testing unauthorised access
Common questions
What happens if a tester exceeds the agreed RoE?+
Any action outside the authorised scope, target list, or technique set falls outside the client's consent and can expose the tester to civil or criminal liability under computer misuse laws, since authorisation is specific to what the RoE actually covers.
Why does an RoE specify emergency stop criteria?+
Some techniques can unintentionally cause outages or data loss on live systems, so the RoE defines conditions under which testing must halt immediately and who must be notified, protecting both the client's operations and the tester from unplanned damage.
Related terms
- Attestation Letter
- A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
- Common Vulnerability Scoring System (CVSS)
- A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
- Red Team Exercise
- A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical)...
- Remediation Verification Test
- A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...