cisagov / ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
1.44k stars 204 forks source link

Add MITRE ATT&CK TTP Mappings to M365 SCBs #937

Open ahuynhMITRE opened 4 months ago

ahuynhMITRE commented 4 months ago

💡 Summary

Adding MITRE ATT&CK TTP Mapping to each baseline policy matching the formatting done in GWS's SCBs.

Motivation and context

The alignment of the M365 SCB policies to their MITRE ATT&CK TTP mappings will allow the user of the SCBs to better understand the impact, specific threat models, and methodologies that are identified with our policies.

The format of the mappings will also mirror the format of the GWS SCBs to ensure consistency between the two products.

Implementation notes

Acceptance criteria

How do we know when this work is done?

ahuynhMITRE commented 4 months ago

moved to blocked due to the mappings still being in draft

schrolla commented 3 months ago

@ahuynhMITRE Are mappings still in draft form? If not, can this work be unblocked? Regardless, with little time left in the sprint, do we want to push this to the next sprint/release?

schrolla commented 2 months ago

Be sure to include mappings in updated Word doc for review as well.