Related Posts
What about Italy? Anyone working there?
Additional Posts in Cyber Security Bowl
Any tips or tricks for CSX certification?
Tell me it’s not true.

New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.



So they are using it as a way of mapping their existing controls to see what coverage they have against attack paths?
Yea, what D1 said — tons of people are familiar with it or have used it hands on — but it’s a framework and “hands on” can mean a variety of things. What are you trying to do?
What are you trying to do with it?
Trying to interview for a job where my role would be GRC, risk assessment and this framework is used heavily. Im trying to find someone who does or has done it from that lens to walk me through real scenarios of how they thought through this and came up with risks/controls. I understand the framework has this but want to go a few layers deeper and understand better
I have found in GRC people just speak to it, but never actually perform any analysis to determine how the organization's security or IT team is using the framework. From a GRC perspective, for your interview you can speak to it as "if I were to evaluate the organization's Security Operations Center (SOC), I would look to see how the team tests for privilege escalation, how did they use the framework to detect and prevent the privilege escalation" Get on the Youtubes and search for MITRE Attack Framework explained.