Map your mitigation coverage to a technique
Map your mitigation coverage with the technique that enables you to detect your organization's overall mitigation strategy.
Before you begin
- Role required: sn_ti.admin, sn_si.admin: write, delete access
- Role required: sn_ti.read: read access
About this task
Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. Each MITRE-ATT&CK technique contains mitigations that you can deploy in your organization to reduce the chance of being attacked. You can use the mitigation coverage to get an overview of your organization's overall mitigation strategy. For example, if an adversary is attacking your organization, you see the kind of coverage that you have to mitigate the attacker's techniques.
The technique, and mitigation information are automatically populated for all the collections and techniques that you have activated. The mitigation coverage definition that you have defined are available for you to select in the technique mitigation coverage.
You can identify mitigations that are relevant to your organization. If a mitigation is relevant, then you can define if the mitigation strategies have been deployed. You can specify if the strategies are applied as part of your organization's SOC Policy. You can also identify if your organization has preventive tools in place to mitigate an attacker's techniques and you can map any security controls that your organization has deployed to minimize security risks. Populate the mitigation coverage (percentage) for each of the records.
After mapping the information for each of the techniques, the mitigation coverage calculator auto populates the Calculated Technique Mitigation Coverage. To calculate the overall mitigation coverage for any technique, the technique mitigation mapping records must be active and relevant to the organization. The records which are inactive and not relevant are not considered for calculating the overall technique mitigation coverage. Based on the values in the Calculated Technique Mitigation Coverage and the mitigation coverage definition, your Overall Technique Mitigation Coverage (Calculated) is populated.
The customizations that you make to the coverage types, colors, or percentages are used in the mitigation coverage mapping and also in the heat map.