Talk With an Expert

ATT&CKing Threat Management: A Structured Methodology for Cyber Threat Analysis

ATT&CKing Threat Management: A Structured Methodology for Cyber Threat Analysis (PDF, 5.07MB)Published: 29 Jul, 2019
Created by
Andy Piazza

Risk management is a principal focus for most information security programs. Executives rely on their IT security staff to provide timely and accurate information regarding the threats and vulnerabilities within the enterprise so that they can effectively manage the risks facing their organizations. Threat intelligence teams provide analysis that supports executive decision-makers at the strategic and operational levels. This analysis aids decision makers in their commission to balance risk management with resource management. By leveraging the MITRE Adversarial Tactics Techniques & Common Knowledge (ATT&CK) framework as a quantitative data model, analysts can bridge the gap between strategic, operational, and tactical intelligence while advising their leadership on how to prioritize computer network defense, incident response, and threat hunting efforts to maximize resources while addressing priority threats.