From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,200 courses taught by industry experts.

Threat management frameworks

Threat management frameworks

- In this lesson, we're going to talk about three threat management frameworks, the Lockheed Martin Cyber Kill Chain, the MITRE Attack Framework, and the Diamond Model of Intrusion Analysis. First, let's talk about the Lockheed Martin Cyber Kill Chain. This model was first developed by the Lockheed Martin Corporation and then released into public domain for everyone to use. The Cyber Kill Chain has a seven step method that starts with reconnaissance and then moves into weaponization, delivery, exploitation, installation, command and control, and action on objectives. The Cyber Kill Chain is a very linear process going from the top all the way to the bottom in sequential order from step one to step seven. The Cyber Kill Chain is considered an older model and uses a linear approach, whereas most of the newer frameworks are a more iterative approach. The first stage is reconnaissance. In the reconnaissance stage, the attacker's going to determine what methods they need to use to complete…

Contents