The cyber threat to critical infrastructure is increasing, prompting cyber government agencies to issue more warnings and advisories for industrial businesses.
Against this backdrop, MITRE has launched EMB3D, a new threat model framework for defenders tasked with protecting operational technology and industrial control systems.
EMB3D provides a knowledge base of cyber threats to embedded devices used in industrial environments.
It allows the user to map those threats with vulnerabilities and flaws systems like the Common Weakness Enumeration and the Common Vulnerabilities and Exposures and MITRE's own TTPs mapping framework, ATT&CK. For each threat, suggested mitigations are focused on technical mechanisms that device vendors should implement to protect against the given threat.
EMB3D is designed to be used by the entire security ecosystem, from device vendors and manufacturers to asset owners, security researchers and testing organizations.
Currently in a pre-release review period, EMB3D will be publicly available in early 2024.
New threats and mitigations will be added and updated over time as new threat actors emerge and security researchers discover new categories of vulnerabilities, threats and security defenses.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Wed, 13 Dec 2023 15:30:28 +0000