Remembering what red teaming is about
With all the discussions about maturity, measurements, and some of the risk management integration ideas that we covered in this chapter, it could be easy to forget why an adversarial red team in an organization is established in the first place.
Part of the job of a red teaming program is to help remove uncertainty and drive cultural change. The big challenge with risk management and measurement is to come up with quantifiable metrics that enable better decision-making. The more that is known, the less uncertainty there is. Penetration testers and red teamers are there to help discover more of the unknowns. Also, red teaming itself does not stop with penetration testing nor with offensive computer security engineering; it is much broader in nature.
Along the lines of an old Persian proverb, also stated by Donald Rumsfeld in a DoD briefing (https://archive.defense.gov/Transcripts/Transcript.aspx?TranscriptID=2636), these are the possible...