-
-
Notifications
You must be signed in to change notification settings - Fork 118
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
How to implement RE&CT in my organization #51
Comments
Hi @dsvetlov We agree with your opinion. The problem which we were facing was to not go too deeply in response actions as those varies in every environment, but at the same time not be too high level (Preparation: Prepare for incident ;). For example we suggest some of the tools which we tested and which worked well for us (like a |
Hi @dsvetlov!
You are absolutely right. We developed Response Actions in the way to:
Let me go through the operationalization process step by step:
That's supposed to be done on the user side. There are many unique requirements, internal specifics, systems and methods to execute a particular Response Action in an organization. So we better focus on the Response Actions development (the variety) in the way they are right now, rather than going deeper in some specifics. We also need to integrate Data Needed and Mitigation Systems to provide analytics about the value of one system/data in comparison to the others. We believe that it would be more valuable for the community. |
This specific topic has been on my mind since first introduction to the project, and I'd just like to share some thoughts on how I think organizations could leverage ATC-RE&CT. Nirvana-state usage of RE&CT.
From a practical perspective, I'm trying to push an organization I've worked with in the past towards RE&CT for SOAR.
Would love to hear how others are leveraging RE&CT in their organization or your views on how it could be leveraged. |
The use cases and implementation process for this framework are not clear. Kindly ask everybody who is concerned to discuss it.
From my point of view. These "tactics and technics" are "theoretical" or very high-level to be actionable for a wide audience. Hence they should be clarified and detailed for each organization.
Hence atc-react could be used as a skeleton of RA catalog in Atomic Threat Coverage. But each RA should be modified for certain needs and processes of an organization.
These are my thoughts about atc-react and it's use cases. I think that @yugoslavskiy and @mrblacyk did a great job and we need to think about how to make this data more actionable.
Please share your thoughts and opinions, because I'm an active ATC user and want to know how other companies use it.
The text was updated successfully, but these errors were encountered: