Prioritizing improvements to the security posture
Improving the security posture of an organization is daunting. What will make the biggest impact? Where to start? Will the changes stop adversaries? Are the necessary defensive technologies in place, but need to be reconfigured? The questions can go on and on. Organizations only have so many resources to apply, so it is important to prioritize these investments.
We discussed in the previous section how to use the MITRE ATT&CK™ model to assist not only in hunting, but also in IR operations. We can use additional models, such as the Lockheed Martin Cyber Kill Chain.
Lockheed Martin Cyber Kill Chain
As we discussed in Chapter 1, Introduction to Cyber Threat Intelligence, Analytical Models, and Frameworks, the Lockheed Martin Cyber Kill Chain is a response model for identifying activities that an adversary must conclude in order to complete a campaign. We can use this model to assist in the improvement of the security posture...