
25.10.2022
|Bruno Blumenthal
|Presentation
Most Security Operations Centers (SOCs) rely on use cases to structure and manage their detection and response capabilities. A common starting point for developing these use cases is the MITRE ATT&CK Framework. Although ATT&CK was originally created as a taxonomy for threat intelligence — not as a dedicated use-case framework — it contains valuable insights that can help organizations identify and prioritize relevant detection use cases.
Defining these use cases is only the first step. The real challenge lies in implementing them efficiently and keeping up with evolving threats and business priorities. To address this, we need a dynamic approach that allows us to prioritize continuously and adapt to changes in the threat landscape.
This is where principles from agile software development come into play. In this talk, I will demonstrate how to combine a data-driven method for prioritizing ATT&CK techniques with agile practices to guide their implementation. This approach enables you to use your resources more effectively and focus on the right use cases at the right time. Agile methods also ensure that your detection capabilities grow and evolve continuously—just like the threats they are designed to defend against.
Click play to load and play the video from Youtube.
I have been involved in information and cyber security for over 20 years. I support our clients in the further development and optimization of their security governance and organization. When building future-proof security architectures, I focus on the optimal interaction between technology and people. I am also involved in further training in the field of cybersecurity as chief expert for the Information Security Manager examination with a federal diploma.