CSA UK Applying MITRE ATT&CK Cloud and Microsoft K8 Matrix

The Cloud Security Alliance UK chapter is presenting a series of sessions to provide CISO's, Cloud Security Architects, DevSecOps and SOC teams a breadcrumb roadmap of how to apply the recently published (late 2019) MITRE ATT&CK for the Cloud and also take influence from Microsoft’s recent Threat matrix on Kubernetes (K8).



 

We are seeking feedback or additional items you would like us to cover. 


The proposed series of sessions will cover:

 

Session 1: [ Author/Presenter: Stephen Owen] 90 mins planned online 24th June

  1. CSA session on "What is MITRE ATT&CK and Cloud" and what benefits it brings to each of the stakeholders 
    1. What is MITRE ATT&CK Enterprise and Cloud
    2. Where to start
    3. How to take advantages of the current MITRE ATT&CK Cloud and combining with Microsoft’s K8 Matrix; 
    4. Suggested practices to follow targeted to each of the below roles:
      1. Cloud Security Architects
      2. DevSecOps
      3. SOC Team 
      4. Cloud/CISO Leadership 
    1. Where CSA UK need help: Support Groups
    1. Mapping CSA CCM to MITRE ATT&CK Cloud techniques, e.g. Credentials in file ID T1081 {hint... Developers placing cred in config files/code in Git or even in containers} 
    2. Mapping Cloud Security architecture reference patterns to MITRE ATT&CK Cloud 


Session 2: [ Author/Presenter: TBC]

  1. How to use the CSA CCM and MITRE ATT&CK Cloud


Session 3: [ Author/Presenter: Stephen Owen & Fran]

  1. How to use Cloud Security architecture reference patterns with MITRE ATT&CK Cloud 

 

We would welcome early comments to the above to help shape the sessions and CSA UK Chapter research agenda.

 

Stephen Owen 

CSA UK Chapter board

LinkedIn https://www.linkedin.com/in/stephen-owen-data-protection/

Comments

Anonymous said…
I'm very interested in hearing about this.

Popular posts from this blog

Understanding ISO 27001 certification

What is hybrid cloud computing?