Skip to content

MITRE ATT&CK

What is MITRE ATT&CK?

A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used for threat modeling and security assessment.

Information Security

What the standards actually require on mitre att&ck

Requirements naming mitre att&ck across 6 standards, quoted from the control text.

MITRE ATT&CK8 controls

Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable o...

MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation · MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control
MITRE D3FEND2 controls

Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information As...

MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology · MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology

FIRST CSIRT Services Framework v2.1 Service Area 4 - Situational Awareness. SCOPE: maintaining + sharing operational + tactical + strategic awareness of the cyber threat landscape relevant to the constituency.

FIRST-CSIRTF-SA4-SituationalAwareness · Service Area 4 - Situational Awareness and Threat Intelligence

HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;

HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks
ISMAP (Japan)1 control

ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...

ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management

Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security...

KNCF-Detect-Monitoring-SIEM-SOC-Threat-Intel-CTI-MITRE-ATT-CK-EDR-XDR-MDR-24-7-Continuous · Kuwait NCF Detect + Monitoring + SIEM + SOC + Threat Intel + EDR + XDR + 24/7

Questions people ask about mitre att&ck

What is MITRE ATT&CK?
A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used for threat modeling and security assessment.
Why is MITRE ATT&CK important for compliance?
MITRE ATT&CK is a key concept in Information Security. Understanding mitre att&ck helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address MITRE ATT&CK?
MITRE ATT&CK appears in the requirement text of MITRE ATT&CK, MITRE D3FEND, FIRST CSIRT Services Framework and Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), ISMAP (Japan). Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about MITRE ATT&CK?
Explore our compliance framework pages to see how mitre att&ck applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how MITRE ATT&CK applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.