69 Purple-team / adversary emulation
draft
A periodic adversary-emulation exercise: the attacks these controls claim to stop are actually run against the tenant, and three questions are answered — was it blocked, was it detected, and did anyone act on the alert. Its output is the evidence that the controls you deployed actually fire; without it, every claim they make is untested.
Caveats
- It has no Admin Console screen and changes no setting — the deliverable is the evidence, so an exercise nobody writes up buys nothing.
- It tests only what you thought to emulate — a clean report bounds the attacks you imagined, not the ones you did not.
This is a process control — it is carried out offline, so there is no Admin Console walkthrough to show.
Ongoing maintenance
- requires a human Per interval: run the exercise and write findings with owners.
How to verify
-
Check the most recent exercise report exists, is within the agreed interval, and each finding has an owner and a remediation state.
draft v0.0.1 Assure policy #21 · #12 ↗