QuestionQ52

Security Operations

A systems administrator decides to take a programmatic approach in cataloging system resiliency to both new and existing attack patterns. Which of the following should the systems administrator use?

Explanation

MITRE ATT&CK is used programmatically (e.g., via the ATT&CK Navigator) to map and catalog an organization's resiliency and defensive coverage against known adversary tactics and techniques, and it is continuously updated as new attack patterns emerge, making it the standard tool for this exact use case. CAPEC catalogs attack patterns themselves rather than an organization's resiliency against them, STRIDE is a design-time threat-modeling mnemonic, and OWASP focuses on web application security guidance rather than a structured, ongoing resiliency catalog.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!