Govur University Logo
--> --> --> -->
...

To demonstrate the organization's security maturity against a specific threat landscape, what is the MOST effective way to leverage the ATT&CK framework for quantitative risk assessment and communication to non-technical stakeholders?



To demonstrate an organization's security maturity against a specific threat landscape using the ATT&CK framework for quantitative risk assessment and communication to non-technical stakeholders, the most effective way is to map known threats to specific ATT&CK techniques, assess the likelihood and impact of these techniques being exploited, and then quantify the risk associated with the organization's current defenses against them. This involves several key steps. First, understand the ATT&CK framework itself, which is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. 'Tactics' represent the 'why' of an adversary's action, such as initial access or execution, while 'techniques' represent the 'how' they achieve those tactics, like phishing or command-and-scripting. Next, define the specific threat landscape relevant to the organization. This means identifying the types of adversaries (e.g., nation-state actors, cybercriminals) and their common objectives and methods that pose the greatest risk. Then, map these threat actors and their typ....

Log in to view the answer



Redundant Elements