

MITRE: To test and gain confidence in MSSPs, use ATT&CK framework
source link: https://www.csoonline.com/article/3646551/mitre-to-test-and-gain-confidence-in-mssps-use-attck-framework.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

MITRE: To test and gain confidence in MSSPs, use ATT&CK framework
Companies have greater confidence in their own security teams than in MSSPs, according to a new survey. To better evaluate service provider capabilities, companies can apply techniques used by the ATT&CK (adversarial tactics, techniques, and common knowledge) assessment framework to MSSPs, MITRE says.
Enterprises have a substantially lower level of confidence in their MSSP (managed security services provider) support than they do in their in-house capabilities, according to a recent survey commissioned by R&D foundation MITRE Engenuity.
To address these concerns, the organization — part of MITRE, a not-for-profit corporation that operates federally funded research facilities focusing on safety and security — has a recommendation. To better evaluate and gain a sense of confidence in service providers' capabilities, MITRE says, companies should apply the ATT&CK (adversarial tactics, techniques, and common knowledge) security evaluation framework, often used for endpoint vendor assessment, to MSSPs.
To that end, MITRE has come out with an open-source threat intel platform, MITRE ATT&CK Evaluation for Managed Security Services, an extension to the existing MITRE ATT&CK evaluations program, intended to zoom in on what it calls the "people responsible for keeping us secure."
To understand how companies use managed security services, MITRE Engenuity commissioned a survey conducted by Cybersecurity Insiders — a global online community of cybersecurity professionals. The survey polled 311 IT security professionals in industries including technology, healthcare, retail, government, and finance,
While 68% of the respondents used MSSP/MDR (managed detection and response), almost half (47%) expressed low confidence in managed services technology and people, according to the survey. Moreover, 44% confirmed lack of confidence in managed services security processes.
Companies trust in-house staff more than MSSPs
“Based on the results of this survey, it is clear that the participants’ level of confidence in their managed services is much lower compared to their in-house security people and technology, in which 78% reported feeling confident,” said Holger Schulze, CEO of Cybersecurity Insiders, in a press release.
Sixty-five percent of the respondents confirmed they use a "threat-informed" defense approach to their security efforts, tapping knowledge databases of adversary techniques and technology to protect against cyberattacks, and about two-thirds of those use ATT&CK evaluations to assess their endpoint vendor decisions, according to the report.
A major chunk of the participants have adopted offensive testing approaches while onboarding security technology. Among these, 39% use breach and attack simulation tools, 34% turn to external red teaming services, and 30% stick with in-house red teaming. Red teaming refers to the process of simulating the entire life cycle of a real-world cyberattack.
While 59% of respondents used offensive testing on the selection process for products, only 53% used this type of testing on services.
A more "alarming" finding, according to the survey report, is that 28% of respondents follow a “no news is good news” kind of approach when it comes to validating their security performance, rather than engage in offensive testing.
Though survey respondents expressed more confidence in their own security teams than in third-party service providers, they also conveyed doubts about in-house teams as well. Forty-two percent of those polled blamed lack of training as one of the key reasons for their lack of confidence in the security capabilities of their own organizations. Thirty-eight percent and 35% pin their doubts on inefficient hiring and lack of technology, respectively.
MITRE offers ATT&CK evaluation for MSSPs
Noting the lack of confidence in managed service providers, issues with in-house security teams, and the high percentage of organizations that do not do offensive testing of either security products or MSSPs, the report suggests that organizations need to adopt informed evaluation processes for managed services.
“The ATT&CK Evaluations for Managed Services will be trying to showcase how any given participant addresses the threat,” says Frank Duff, MITRE Engenuity's general manager of ATT&CK Evaluations.
The evaluation framework comprises multiple test scenarios that can be applied to managed services, assessing how they respond. According to Duff, the data obtained through the new ATT&CK capability will provide users with information to review and decide whether the service in question is right for them in terms of context, form, scale and efficiency.
"In the results, we will describe what threat we emulated, what techniques we executed and how, and what context the vendor did or did not provide around that behavior. We will show their results that they provided to us as if we were one of their customers," Duff says.
Recommend
-
39
Posted 22 hours ago2021-04-26T00:22:00-05:00 by remotephone MITRE ATT&CK Defender - New and EducationalI was lucky enough to be able to go through the MITRE ATT&CK Defender training and certifi...
-
5
Monday, 19 July 2021 15:07 Why Network Detection and Response strengthens the MITRE ATT&CK framework By Glen Maloney ExtraHop ...
-
6
What is MITRE's ATT&CK framework? What red teams need to knowThe ATT&CK framework, developed by MITRE Corp., has been around for five years and is a living, growing document of threat tactics an...
-
5
The MITRE ATT&CK Framework: A Comprehensive Guide Data Security
-
11
Press Release D3 Security Launches D3 Chronos, a SOAR Package for MSSPs that Prioritizes Rapid Deployment and Return on Investment
-
11
Opinion The changing role of the MITRE ATT@CK framework Organizations are usin...
-
7
2024's blog how to gain confidence in...
-
12
News New “MITRE ATT&CK-like” framework outlines software supply chain attack TTPs
-
7
News Expel announces MDR for Kubernetes with MITRE ATT&CK framework alignment Exp...
-
3
Cybersecurity training alignedwith the MITRE ATT&CK framework Mar 12, 2024 OffS...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK