Rules of Engagement Template

Authorization

  • Sponsor / system owner:
  • Written authorization reference:
  • Assessment lead:
  • Start and end time, including timezone:
  • Approved assessors:
  • Emergency contacts:

Scope

  • In-scope hosts, applications, accounts, repositories, and cloud projects:
  • Explicitly out-of-scope assets:
  • Allowed test accounts and data:
  • Third-party dependencies excluded from testing:

Permitted Methods

  • Approved tools and techniques:
  • Maximum request/concurrency rate:
  • Allowed hours:
  • Social engineering status:
  • Denial-of-service status:
  • Physical testing status:
  • Data-access ceiling:

Stop Conditions

Stop immediately for safety impact, unexpected third-party data, service instability, scope ambiguity, uncontrolled cost, lost evidence integrity, or a request from the owner.

Evidence and Privacy

  • Storage and encryption:
  • Retention and destruction:
  • Screenshot/redaction rules:
  • Hashing and chain-of-custody process:
  • Prohibited data:

Communications

  • Daily status format:
  • Critical-finding escalation:
  • Incident declaration path:
  • Final deliverables:
  • Retest and closure:

Sign-Off

  • System owner:
  • Assessment lead:
  • Legal/privacy review when required: