Mapping OSCAL to Attack Techniques #27
xee5ch
started this conversation in
Show and tell
Replies: 1 comment
-
@xee5ch - I discussed this mapping idea long ago (1-1.5 years ago) with the D3FENSE tech lead. I wanted to use OSCAL for the mapping by generating the D3FENSE capabilities in OSCAL CDef with links to the ATT&CK threats mapped by MITRE. The answer I received was positive only under the condition of being funded to do so. There might be other ways of representing the information but research would be needed and the best approach will depend on the use case. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I discovered another interesting research project out of MITRE, CICAT:
It would be wonderful to 1) expand this beyond applications beyond ICS and 2) most importantly map attacks and defenses from ATT&CK mapping to structured system data about its defenses written in OSCAL.
Anyone agree? Thoughts?
Beta Was this translation helpful? Give feedback.
All reactions