Rules of Engagement (ROE) document provides certain rights and restriction to the test
team for performing the test and helps testers to overcome legal, federal, and policy-related
restrictions to use different penetration testing tools and techniques.
What is the last step in preparing a Rules of Engagement (ROE) document?
A.
Conduct a brainstorming session with top management and technical teams
B.
Decide the desired depth for penetration testing
C.
Conduct a brainstorming session with top management and technical teams
D.
Have pre-contract discussions with different pen-testers
D
C Ecsa v8 page 176 “Steps for for framing ROE”
The last step is “Conduct a brainstorming session with top management and technical teams” according to the ECSAv8 Module 05 Rules of Engagement page 176.
Module 05, Page 176
Steps
1. Estimate cost, time, and effort that organization can invest. => budget
2. Decide on desired depth for penetration test. ==> scope
3. Have pre-contract discussions with different pen testers. ==> quotation
4. Conduct brainstorming sessions with the top management and technical teams ==> decide