Browse Definitions :
Definition

red team-blue team

Contributor(s): Matthew Haughn

Red team-blue team is a simulation and training exercise where members of an organization are divided into teams to compete in combative exercises. In information security (infosec), the exercise is designed to identify vulnerabilities and find security holes in a company's infrastructure. The war games are also used to test and train security staff.

Generally, members of the security team split into two groups: a red team and a blue team. The red team plays the role of a hostile force and the blue team plays defense as the organization. The red team's goal is to find and exploit weaknesses in the organization's security as the blue team works to defend the organization by finding and patching vulnerabilities and responding to successful breaches.

The terms red team and blue team are often used to refer to cyberwarfare in contrast to conventional warfare. War games function as a means of testing for the worst case scenarios of coordinated, focused attacks by skilled attackers. While testing infrastructure and personnel are common in branches of the military, they are increasingly popular in enterprise, government, finance, critical infrastructure and key resources (CIKR) and many other security and IT-focused institutions.

This was last updated in November 2017

Continue Reading About red team-blue team

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

  • smart contract

    A smart contract, also known as a cryptocontract, is a computer program that directly controls the transfer of digital currencies...

  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces. A...

SearchSecurity

  • challenge-response authentication

    In information security, challenge-response authentication is a type of authentication protocol where one entity presents a ...

  • Secure Shell (SSH)

    SSH, also known as Secure Shell or Secure Socket Shell, is a network protocol that gives users, particularly system ...

  • honeypot (computing)

    A honeypot is a network-attached system set up as a decoy to lure cyberattackers and to detect, deflect or study hacking attempts...

SearchHealthIT

SearchDisasterRecovery

  • virtual disaster recovery

    Virtual disaster recovery is a type of DR that typically involves replication and allows a user to fail over to virtualized ...

  • tabletop exercise (TTX)

    A tabletop exercise (TTX) is a disaster preparedness activity that takes participants through the process of dealing with a ...

  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a data center.

SearchStorage

  • exbibyte (EiB)

    An exbibyte (EiB) is a unit used to measure data capacity.

  • zebibyte (ZiB)

    A zebibyte (ZiB) is a unit used to measure computing and storage capacity.

  • tiered storage

    Tiered storage is a way to assign different categories of data to various types of storage media with the objective of reducing ...

Close