TLP WHITE - FINAL Information Sharing and Data Protection The entity is responsible for conducting a TLPT assessment and sharing deliverables in accordance with the requirements of all relevant authorities. Such authorities may wish to collaborate on information sharing, where appropriate, and consistent with data protection and cross-jurisdictional information sharing norms. Effective controls should be in place to protect details of all information related to TLPT activities. Controls should reflect the sensitivity of the information. Information should be distributed on a need-to-know basis. TLPT Fundamental Elements To meet the overall goals of TLPT, the G7FE-TLPT set out six fundamental elements for authorities and entities to consider when developing and conducting TLPT, providing clarity on the responsibilities of the different stakeholders at each phase. In general TLPT comprises the following phases: Scoping and Risk Management, Threat Intelligence, Penetration Testing and Closure. Element 1: Scoping and Risk Management There are inherent potential risks associated with TLPT for all stakeholders. In line with the potential risk, the G7FE-TLPT place high priority on clearly defining the scope of the test and applying effective risk management controls throughout the entirety of the assessment. Roles and Responsibilities The White Team3 is responsible for ensuring appropriate risk management controls are in place and getting agreement on the scope of the test with the relevant stakeholders. As the test would be conducted without the foreknowledge of the Blue Team4 to enable the Red Team5 to effectively assess the entity’s resilience capabilities, the White Team is encouraged to perform the project management role throughout the assessment process including the Scoping and Risk Management phase. Scope Primarily, the test scope should be based on an assessment of the critical functions and services of the entity, which in turn will inform decisions on the test’s duration and confirm inclusions or exclusions of parameters. The entity should identify the underlying people, processes and technology supporting those critical functions and services, including third party providers (such as IT service providers and supply chain relationships). If the test requires the inclusion of third party providers within the scope, it is the responsibility of the entity to liaise and ensure the participation of the third party provider. 3 The White Team is the group responsible for coordinating an engagement between a Red Team of simulated threat actors and a Blue Team of actual defenders of their entity’s use of information systems. During a test, the White Team enforces the rules of the exercise, observes the exercise, resolves any issues that may arise, receives all requests for information or questions and ensures that the test is executed in the intended manner. 4 The Blue Team is the group responsible for defending an entity’s use of information systems by maintaining its security posture against a group of simulated threat actors (i.e. the Red Team). 5 The Red Team is the group of testers, authorised and organised to emulate a potential actions of a threat actor or exploitation capabilities against an entity’s security posture. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 3

Select target paragraph3