-
Notifications
You must be signed in to change notification settings - Fork 240
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add MITRE ATT&CK Mappings to current SCBs #1106
Add MITRE ATT&CK Mappings to current SCBs #1106
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Main formatting considerations:
Bullets should start with the parent technique. If there are sub-techniques then list these as sub bullets for each baseline.
The techniques are formatted as [T1566:Phishing]. Let's add a space after the colon for all, [T1566: Phishing].
For consistency with GWS let's be sure to reference the parent technique for any sub-techniques.
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
updated the mappings to do the following: - add in reference parent ttp mapping - format sub ttp mappings as sub bullets to these parent ttps - added a space after the ":" for each policy
thanks @mitchelbaker-cisa updated the mappings to do the following:
|
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks Andrew, looks good!
@nanda-katikaneni good to merge! |
🗣 Description
Added MITRE's ATT&CK TTP mappings and links to applicable security control baselines (SCBs) policies matching the format seen in GWS' SCBs
💭 Motivation and context
This update to the SCBs is required because it provides additional context into the tactics, techniques, and protocols the policies are attempting to harden against. This will also align the M365 SCBs with the GWS SCBs that currently have the mappings.
Closes #937
🧪 Testing
✅ Pre-approval checklist
✅ Pre-merge checklist
PR passed smoke test check.
Feature branch has been rebased against changes from parent branch, as needed
Use
Rebase branch
button below or use this reference to rebase from the command line.Resolved all merge conflicts on branch
Notified merge coordinator that PR is ready for merge via comment mention
✅ Post-merge checklist