Countermeasure
What is Countermeasure?
An action, device, procedure, or technique that reduces a threat, vulnerability, or attack by eliminating or preventing it, minimizing harm, or enabling discovery.
Frameworks that govern countermeasure
What the standards actually require on countermeasure
Requirements naming countermeasure across 6 standards, quoted from the control text.
X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application · ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MITRE ATT and CK + Network Modular Risk Assessment →China may take reciprocal measures against countries/regions that adopt discriminatory prohibitions or restrictions against China in personal-information protection.
PIPL-Art43 · Reciprocal Countermeasures →Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information As...
MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology · MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology →Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined]
NIST800-RA-6 · Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined] →Where in scope, the tester must consider AV, EDR, IDS, and similar controls and use evasion techniques that mirror realistic threat actor tradecraft while leaving sufficient logs for blue team replay.
PTES-EX-2 · Countermeasure Evasion and Anti Forensics →Provide proactive reporting to the board on changing threats and the countermeasures in place.
ASIC-CR-RR-3 · Proactive board reporting during incidents →Questions people ask about countermeasure
What is Countermeasure?
Why is Countermeasure important for compliance?
Which compliance frameworks address Countermeasure?
Where can I learn more about Countermeasure?
See how Countermeasure applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.