home/glossary/Red Team

Red Team

nounid 3796·updated May 12, 2026
candidate

A group of people authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The Red Team’s objective is to improve enterprise Information Assurance by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders (i.e., the Blue Team) in an operational environment.

MWE

Classifications

Entity Type

Role0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

60%llm-generatedllm:claude-haiku-4-5

Information Class

85%llm-generatedllm:claude-haiku-4-5

Variants

alternatephrasing
Red-Team
plural
Red Teams
possessive
Red Team's
pluralpossessive
Red Teams'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
A group authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s cybersecurity posture.
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures1 senseview framework →
§1
An independent group that challenges the cyber resilience of an organisation to test its defences and improve its effectiveness. A red team views the cyber resilience of an FMI from an adversary’s perspective.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
A group of people authorized and organized to emulate a potential adversary's attack or exploitation capabilities against an enterprise's security posture. The red team's objective is to improve enterprise information assurance by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders in an operational environment.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
A group of people authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The Red Team’s objective is to improve enterprise Information Assurance by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders (i.e., the Blue Team) in an operational environment.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
A group of people authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The Red Team’s objective is to improve enterprise Information Assurance by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders (i.e., the Blue Team) in an operational environment.
Information Technology Laboratory Computer Security Resource Center Glossary1 senseview framework →
§1
A group of people authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The Red Team’s objective is to improve enterprise cybersecurity by demonstrating the impacts of successful attacks and by demonstrating what works for the defenders (i.e., the Blue Team) in an operational environment. Also known as Cyber Red Team.

Outgoing relationships

related

Incoming relationships

related