Skip to Content
The Cybersecurity Control Playbook
book

The Cybersecurity Control Playbook

by Jason Edwards
April 2025
Intermediate to advanced
544 pages
20h 19m
English
Wiley
Content preview from The Cybersecurity Control Playbook

7Mapping Threats to Controls Using MITRE ATT&CK

Today's threat actors are more sophisticated, persistent, and diverse than ever before. As organizations increasingly rely on digital infrastructures, understanding how adversaries operate—and, more importantly, how to defend against them—has become a critical priority. This is where threat mapping comes into play. It's not enough to have security controls; organizations must ensure those controls align with real‐world threats. The challenge is clear: how do you know what techniques attackers will use and whether your defenses can handle them? Enter the MITRE ATT&CK framework.

MITRE ATT&CK has emerged as one of the most powerful tools for security professionals aiming to map known adversarial techniques to their existing defenses. By leveraging the framework, organizations can take a structured, data‐driven approach to understanding how attackers behave once inside the network. Instead of relying on theoretical models or generic “best practices,” MITRE ATT&CK allows teams to base their defenses on documented tactics, techniques, and procedures (TTPs) observed in real‐world attacks. The result? A defense strategy that is as dynamic and evolving as the threats themselves.

This chapter delves into how organizations can implement a robust threat‐mapping strategy using MITRE ATT&CK. We will walk through the core concepts of threat mapping, explore the role of leadership in driving these exercises, and discuss how tools like artificial ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Emerging Threats and Countermeasures in Cybersecurity

Emerging Threats and Countermeasures in Cybersecurity

Gulshan Shrivastava, Rudra Pratap Ojha, Shashank Awasthi, Kavita Sharma, Himani Bansal

Publisher Resources

ISBN: 9781394331857