Mapping the ATT&CK Framework to CIS Controls

This is a wonderful illustration of the process that many of us should consider working through – how does a particular threat framework map to our existing security framework.  In this situation, the author is attempting to map the ATT&CK framework to the CIS Critical Controls, but this exercise could just as easily have involved NIST or FFIEC or another framework.  Consider the value of exploring and recognizing your strengths and weaknesses in a more real-time sense.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s