Answered step by step
Verified Expert Solution
Question
1 Approved Answer
You are a security analyst working on a Department of Defense contract. Since your organization supports a government agency, you are required to use the
You are a security analyst working on a Department of Defense contract. Since your organization supports a government agency, you are required to use the NIST Risk Management Framework. Your supervisor wants to prioritize implementation of security controls based on threat capabilities as identified in the MITRE ATT&CK Framework. This way you can prioritize mitigation of the most serious threats as you work to attain compliance.
Goa
You must use the MITRE ATT&CK Navigator tool, to develop a prioritized list of adversary techniques that should inform the implementation of countermeasures per NIST SP r
Tasks:
Go to Groups MITRE ATT&CK and select three Advanced Persistent Threat groups APT
a The groups must be based in Russia, China, Iran, or North Korea.
b They must be known to target the defense industry or the US Government from the Threat Groups option.
c Be sure to select APT groups from at least two different countries.
Using MITRE ATT&CK Navigator, create three individual ATT&CK Navigator layers one for each APT
Hint: See MITRE ATT&CK Navigator Demo for a quick tutorial.
Recommendation: Using Version will make ProjectPart easier.
Create a consolidated ATT&CK Navigator layer that aggregates the techniques of all three selected APTs. Your final ATT&CK Navigator build should have four layers: three with one APT each, and one that combines the other three.
Export your layers to an Excel spreadsheet and upload to the Project assignment in DL The spreadsheet you submit should have four worksheets tabs three showing APT each, and one showing the combined highlighted techniques. Hint: If you export a JSON file as well, it may make Part of this project easier.
Using the report template, create an executive summary level report that includes the following sections:
a Provide an overview of each APT and rationale for selection.
b Separate the techniques used by the three selected APTs into three risk categories high moderate, and low
c Focus on the techniques identified in Task b as being High Risk. Place them in order according to priority of mitigating them. Using information from Techniques Enterprise MITRE ATT&CK rationalize your choice.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started