Which standard framework maps attacker techniques and sub-techniques to specific detection data sources and mitigation controls, making it highly useful for continuous security monitoring?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because MITRE ATT&CK maps adversary tactics, techniques, and procedures (TTPs) to specific data sources, detection opportunities, and mitigations, making it ideal for building and improving detection coverage in a SOC. A is wrong because NIST SP 800-61 is an incident response guide, not a detection framework.
Full explanation below image
Full Explanation
B is correct because MITRE ATT&CK maps adversary tactics, techniques, and procedures (TTPs) to specific data sources, detection opportunities, and mitigations, making it ideal for building and improving detection coverage in a SOC. A is wrong because NIST SP 800-61 is an incident response guide, not a detection framework. C is wrong because CIS Benchmarks provide system hardening guidance, not attacker technique mappings. D is wrong because OWASP Top 10 focuses on web application vulnerabilities, not enterprise detection.