Services
|
Red Team Services / Tiger Team Services
Commonwealth Security Services defines red teaming to be an "authorized, adversary-based assessment of facilities and network resources." Authorized means someone with legal control of the facility, system, or entity to be red teamed has agreed to the process. Adversary-based means that the activity is centered around what would one or more adversaries do if they were attacking the target. This means taking into account the adversaries’ knowledge, skills, commitment, resources, and culture. Assessment means one is making a judgement, possibly a comparison, of the state of the target with respect to actions by the adversary. We deliberately exclude security because red teaming doesn’t necessarily involve attacks — we have red teamed adversary reactions to potential business decisions. Commonwealth Security Services suggests that red team assessments be performed throughout the system lifecycle but especially in the design and development phase where cooperative red team assessments cost less, and critical vulnerabilities can be uncovered and mitigated more easily.
Red team assessments are a flexible tool that organizations use to identify critical vulnerabilities; understand threat; deliver effective and secure components, systems, and plans; and consider alternative strategies and courses of action. These assesments are the most "Real World" look at the true status of the security of a system available.
|