Annex V Content of the red team test report (Article 12(2))
LEU20251190EN110120250213EN0001.0005261261
The red team test report shall contain information on at least all of the following:
- (a)information on the performed attack, including:
- (i)the targeted critical or important functions and identified ICT systems, processes and technologies supporting the critical or important function, as identified in the red team test plan;
- (ii)summary of each scenario;
- (iii)flags reached and not reached;
- (iv)attack paths followed successfully and unsuccessfully;
- (v)tactics, techniques and procedures used successfully and unsuccessfully;
- (vi)deviations from the red team test plan, if any;
- (vii)leg-ups granted, if any;
- (i)
- (b)all actions that the testers are aware of that were performed by the blue team to reconstruct the attack and to mitigate its effects;
- (c)discovered vulnerabilities and other findings, including:
- (i)vulnerability and other finding description including their criticality;
- (ii)root cause analysis of successful attacks;
- (iii)recommendations for remediation including indication of the remediation priority.
- (i)