Back to glossary

Rules of engagement

2 min read

In offensive security, rules of engagement are the written agreement that defines exactly what a test may and may not do: the scope, the timing, the permitted techniques, the systems that are off limits, and who to call if something breaks. They are agreed before any testing starts and they authorise the whole exercise.

July 29, 2026
Compartir:

How it works

Rules of engagement turn a vague brief into a bounded, authorised operation. The document fixes the target scope (which domains, ranges, applications and accounts are in and out), the window in which testing may run, the techniques that are allowed and forbidden (for example, whether denial-of-service or social engineering is permitted, whether data may be exfiltrated to prove impact), and the handling of any real data encountered. It names emergency contacts on both sides and a deconfliction procedure so a genuine incident during the test is not mistaken for the test, or vice versa. Crucially it records who has the authority to approve testing against each asset, which is what protects both the tester and the client legally.

What goes wrong

The document that no vendor of security products can write, because they are not in the room when the work is scoped, is this one. When it is thin, engagements fail in predictable ways: a tester touches a system the client assumed was excluded, a production outage happens during business hours because the window was never pinned down, or a real attacker operating at the same time goes unnoticed because every alert is dismissed as “probably the pentest”. From the offensive side, weak rules also cap the value of the test: if the most sensitive systems are carved out by default, the assessment measures the perimeter and never the part that would actually hurt.

Where this shows up in an audit

The rules of engagement are the first artefact in any report and the reference every finding traces back to: a result is only valid if it was in scope and authorised. We record the agreed scope, the exclusions and the approval chain, and note where a carve-out limited what could be assessed so the reader understands the coverage. This is how we agree scope before an engagement begins, whether the work is a penetration test or an assumed-breach exercise.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.