Rules of Engagement Template
Authorization
- Sponsor / system owner:
- Written authorization reference:
- Assessment lead:
- Start and end time, including timezone:
- Approved assessors:
- Emergency contacts:
Scope
- In-scope hosts, applications, accounts, repositories, and cloud projects:
- Explicitly out-of-scope assets:
- Allowed test accounts and data:
- Third-party dependencies excluded from testing:
Permitted Methods
- Approved tools and techniques:
- Maximum request/concurrency rate:
- Allowed hours:
- Social engineering status:
- Denial-of-service status:
- Physical testing status:
- Data-access ceiling:
Stop Conditions
Stop immediately for safety impact, unexpected third-party data, service instability, scope ambiguity, uncontrolled cost, lost evidence integrity, or a request from the owner.
Evidence and Privacy
- Storage and encryption:
- Retention and destruction:
- Screenshot/redaction rules:
- Hashing and chain-of-custody process:
- Prohibited data:
Communications
- Daily status format:
- Critical-finding escalation:
- Incident declaration path:
- Final deliverables:
- Retest and closure:
Sign-Off
- System owner:
- Assessment lead:
- Legal/privacy review when required: