TLP WHITE - FINAL
Information Sharing and Data Protection
The entity is responsible for conducting a TLPT assessment and sharing deliverables in
accordance with the requirements of all relevant authorities. Such authorities may wish to
collaborate on information sharing, where appropriate, and consistent with data protection and
cross-jurisdictional information sharing norms.
Effective controls should be in place to protect details of all information related to TLPT
activities. Controls should reflect the sensitivity of the information. Information should be
distributed on a need-to-know basis.
TLPT Fundamental Elements
To meet the overall goals of TLPT, the G7FE-TLPT set out six fundamental elements for
authorities and entities to consider when developing and conducting TLPT, providing clarity on
the responsibilities of the different stakeholders at each phase. In general TLPT comprises the
following phases: Scoping and Risk Management, Threat Intelligence, Penetration Testing and
Closure.
Element 1: Scoping and Risk Management
There are inherent potential risks associated with TLPT for all stakeholders. In line with the
potential risk, the G7FE-TLPT place high priority on clearly defining the scope of the test and
applying effective risk management controls throughout the entirety of the assessment.
Roles and Responsibilities
The White Team3 is responsible for ensuring appropriate risk management controls are in place
and getting agreement on the scope of the test with the relevant stakeholders. As the test would
be conducted without the foreknowledge of the Blue Team4 to enable the Red Team5 to
effectively assess the entity’s resilience capabilities, the White Team is encouraged to perform
the project management role throughout the assessment process including the Scoping and Risk
Management phase.
Scope
Primarily, the test scope should be based on an assessment of the critical functions and services
of the entity, which in turn will inform decisions on the test’s duration and confirm inclusions or
exclusions of parameters. The entity should identify the underlying people, processes and
technology supporting those critical functions and services, including third party providers (such
as IT service providers and supply chain relationships). If the test requires the inclusion of third
party providers within the scope, it is the responsibility of the entity to liaise and ensure the
participation of the third party provider.
3
The White Team is the group responsible for coordinating an engagement between a Red Team of simulated threat actors and a
Blue Team of actual defenders of their entity’s use of information systems. During a test, the White Team enforces the rules of
the exercise, observes the exercise, resolves any issues that may arise, receives all requests for information or questions and
ensures that the test is executed in the intended manner.
4
The Blue Team is the group responsible for defending an entity’s use of information systems by maintaining its security posture
against a group of simulated threat actors (i.e. the Red Team).
5
The Red Team is the group of testers, authorised and organised to emulate a potential actions of a threat actor or exploitation
capabilities against an entity’s security posture.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
3