Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spreadsheet phrasing #5

Merged
merged 5 commits into from
Apr 8, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/maxmature.rst
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ To illustrate the impact of leveraging the best practices in the M3TID framework

* CTI: Subscribe to a customized threat intelligence feed.
* DM: Dedicate additional resources to developing and tuning detection analytics for identified adversary techniques.
* T&E: Institute a semi-annual purple team.
* T&E: Institute a semi-annual adversary emulation.

Those changes result in the following updated scores and the accompanying graphs:

Expand Down
4 changes: 2 additions & 2 deletions docs/measuring.rst
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ As a notional example of implementing this assessment and scoring approach, imag
Company A: In-house implementation of a nascent threat-informed defense.

* CTI: The organization has CTI on IOCs and software used across multiple ATT&CK Techniques. Analysts occasionally read freely available generic reports and disseminate IOCs to the rest of the team.
* DM: Despite excellent CTI, the company has not leveraged that CTI effectively to prioritize their investments in Defensive Measures. They automatically apply patches, collect data as per standard best-practices, run a set of imported SIGMA rules, respond to alerts as needed, and do not conduct any deception operations.
* T&E: The company is only minimally investing in Testing & Evaluation, limiting their current testing to an annual penetration test that is not tailored to any specific adversary or set of adversary behaviors.
* DM: Despite excellent CTI, the company has not leveraged that CTI effectively to prioritize their investments in Defensive Measures. They apply patches as needed, have identified critical assets, collect data as per standard best-practices, run a set of imported SIGMA rules, respond to alerts as needed, and do not conduct any deception operations.
* T&E: The company is only minimally investing in Testing & Evaluation, limiting their current testing to an annual purple team that is not tailored to any specific adversary or set of adversary behaviors. A report is generated.

To aid in leveraging this methodology for assessment, this paper is being released with a Proof of Concept spreadsheet-based calculator. The screenshots below are taken from
the Results tab of that calculator.
Expand Down
2 changes: 1 addition & 1 deletion docs/spreadsheet.rst
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Appendix B - Scoring Spreadsheet
================================

As part of the M3TID team implemented the Dimensions, Components, and Maturity Level framework, as well as the
As part of the M3TID project, the team implemented the Dimensions, Components, and Maturity Level framework, as well as the
measurement approach, in an Excel-based tool to make leveraging the M3TID framework more accessible for the
community. The tool has 6 main tabs, described below:

Expand Down
Loading