Mapping ATT&CK to compliance frameworks
As previously discussed, there are a large number of compliance frameworks, and it’s growing every year. In my opinion, the most common frameworks are the Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPPA), Global Data Protection Regulation (GDPR), National Institute of Standards and Technology (NIST) – NIST-181 and NIST 800-53, for example – International Organization for Standardization (ISO) 2001, and Service Organization Control (SOC2). Of course, as mentioned, there are other types of compliance frameworks that might be more applicable to your environment. With a large number of compliance frameworks, it can be confusing to keep track, so finding common mappings helps simplify it. In this section, we are going to map out a few different techniques for different compliance standards.
The first technique that we’ll create is a mapping to T1556...