Annex VI Content of the blue team test report (Article 12(4))


The blue team test report shall contain information on at least all of the following:

  1. for each attack step described by the testers in the red team test report:

    1. list of detected attack actions;

    2. log entries corresponding to these detections;

  2. assessment of the findings and recommendations of the testers;

  3. evidence of the attack by the testers collected by the blue team;

  4. blue team root cause analysis of successful attacks by the testers;

  5. list of lessons learned and identified potential for improvement;

  6. list of topics to be addressed in purple teaming.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod