The engagement may draw on MITRE ATT&CK, red-team rules-of-engagement practice, relevant threat intelligence and customer control frameworks. A framework reference explains how the work is organised; it does not by itself represent certification, accreditation or a regulatory decision.
The schedule is confirmed after scoping and depends on the environment, evidence available and stakeholder access.
Red teaming carries higher operational and reputational risk than a standard penetration test. It requires explicit executive sponsorship, legal authority, deconfliction, stop conditions and agreement on sensitive techniques. It cannot guarantee that every real attacker would be detected or blocked.