This diagram helps illustrate IPDRR coverage per engagement type.
Vulnerability assessments provide an organization the measure or understand the ability to identify or protect against a threat. This great but does not provide the means to understand security operations as a whole. Vulnerability assessments tend to focus on preventive controls.
Because penetration testing focuses
on attack path validation, they can be used to measure not only identification or protection but detection of threat activity and possibly a bit of response. In general,
penetration tests are scoped for maximum coverage is a relatively short time. These tests lead to further understanding of protection and detection against threat activity but do little to understand response or recovery.
Red Teaming allows an organization to explore all aspects of threat activity fully. Red Teaming provides the needed stimulation to engage security operations as a whole. Red Teaming can employ an organization to enable security operations (Blue Team) to utilize their
TTPs through identification,
protection, detection,
response, and recovery from a threat. The level of measurement is shaped by the engagement plan and determined by the goals.