The rules of engagement, distinct from scope, set how the test is conducted: the timeline and any work breakdown, the locations and whether remote or on-site testing applies, the times of day permitted for testing, whether disruptive activities such as denial-of-service or stress testing are in or out of scope (and if in, that they run against a non-production environment mirroring production), whether the organisation's defenders will be informed (a blind or coordinated test, including whether traffic blocking or shunning is acceptable), and, where social engineering is in scope, the pretexts approved in writing. Scope creep is controlled through agreed start and end dates and a defined window for any retesting.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.