|
|
By Jason Georgoulis
|
The MITRE ATT&CK framework is a community-led initiative to provide a globally accessible knowledge base of common methods used by adversaries that is intended to help organizations prepare for potential threats. ATT&CK describes the targets and tactics of adversaries while also providing mitigation activities that may be helpful in reducing the risks associated with particular techniques.
The ATT&CK framework is available for three technology domains—enterprise, mobile, and industrial control systems (ICS). This gives users a more granular set of techniques for each type of system. Understanding how an attacker may attempt to compromise an organization (such as through social engineering or Interactive Remote Access) can help defenders develop and implement internal controls to reduce the risks associated with these types of threats.
Texas RE encourages Responsible Entities to utilize the MITRE ATT&CK framework to strengthen detection and mitigation strategies for cybersecurity threats to better protect the Bulk Electric System.