Which standard framework maps attacker techniques and sub-techniques to specific detection data sources and mitigation controls, making it highly useful for continuous security monitoring?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — b is correct because MITRE ATT&CK maps adversary tactics, techniques, and procedures (TTPs) to specific data sources, detection opportunities, and mitigations, making it ideal for building and improving detection coverage in a SOC. A is wrong because NIST SP 800-61 is an incident response guide, not a detection framework.
Full Explanation
B is correct because MITRE ATT&CK maps adversary tactics, techniques, and procedures (TTPs) to specific data sources, detection opportunities, and mitigations, making it ideal for building and improving detection coverage in a SOC. A is wrong because NIST SP 800-61 is an incident response guide, not a detection framework. C is wrong because CIS Benchmarks provide system hardening guidance, not attacker technique mappings. D is wrong because OWASP Top 10 focuses on web application vulnerabilities, not enterprise detection.