available
in the environment or public, but something such as policy,
procedure, politics,
contracts,
training, etc. prevents implementation or application.
3
The correction or mitigation is not readily available in any industry or sector. Research or additional effort is required to investigate to determine a correction or mitigation plan.
Example Diagram Summarizing Categories
Example snippet from a report showing
how to use category ratingAuthor’s ThoughtsVery few things should be labeled 3. There’s almost
always an acceptable mitigation/workaround.
Many will likely be labeled 2. This should because for policy or process change and could be used to justify additional training.
Anything labeled 1 should be of great
concern to the organization, division, or management. Often indicates alack of effort.
It is important to note that this method of categorization requires open and effective communication between the Red Team and the organization. Internal Red Teams may have the organizational knowledge and experience required to categorize their observations. However,
as most Red Teams(internal or external) are not typically part of the business function being assessed, require a collaborative review and discussion of each observation.
During
Red Team reporting, this method can be used in conjunction with the Pyramid of Pain to illustrate how a specific correction impacts a threat's ability to perform nefarious actions. This knowledge can, in turn, be leveraged to create a prioritization of corrections or organizational modifications.
Share with your friends: