MITRE ATT&CK vs NIST Cybersecurity Framework
MITRE ATT&CK and the NIST Cybersecurity Framework (CSF) are two of the most widely adopted frameworks in cybersecurity. While they serve different purposes, they complement each other to provide comprehensive security guidance.
What is MITRE ATT&CK?
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a common language for describing attacker behaviour across the entire attack lifecycle.
What is NIST Cybersecurity Framework?
The NIST Cybersecurity Framework (CSF) is a set of guidelines, standards, and best practices for managing cybersecurity risk. It organises security activities into five core functions: Identify, Protect, Detect, Respond, and Recover.
Comparison Table
| Aspect | MITRE ATT&CK | NIST Cybersecurity Framework |
|---|---|---|
| Primary Purpose | Describe adversary behaviour | Manage cybersecurity risk |
| Perspective | Attacker-centric (offensive) | Defender-centric (governance) |
| Scope | Technical attack techniques | Organisational security programme |
| Structure | Tactics → Techniques → Sub-techniques | Functions → Categories → Subcategories |
| Update Frequency | Regular (multiple times per year) | Periodic (major revisions less frequent) |
| Industry Adoption | Security operations, threat intel | Governance, risk, compliance |
| Primary Users | SOC analysts, red teams, threat hunters | CISOs, risk managers, compliance teams |
| Measurement | Technique coverage, detection rates | Maturity levels, conformance tiers |
| Compliance Use | Not a compliance framework | Widely used for compliance |
| Detail Level | Highly granular, technical | Strategic, high-level |
| Mapping Capability | Maps to specific attack behaviours | Maps to security controls and outcomes |
| Open Source | Yes, freely available | Yes, freely available |
Framework Structure Comparison
MITRE ATT&CK Structure
Tactics (Why) Techniques (How) Sub-techniques (Details)
───────────── ────────────── ──────────────────────
Initial Access → Phishing → Spearphishing Attachment
→ Valid Accounts → Default Accounts
Execution → Command & Scripting → PowerShell
Persistence → Boot/Logon Autostart → Registry Run Keys
NIST CSF Structure
Functions Categories Subcategories
────────── ────────── ─────────────
Identify → Asset Management → ID.AM-1: Physical devices inventoried
Protect → Access Control → PR.AC-1: Identities and credentials managed
Detect → Anomalies Events → DE.AE-2: Normal activity baselines established
Respond → Response Planning → RS.RP-1: Response plan executed
Recover → Recovery Planning → RC.RP-1: Recovery plan executed
How They Complement Each Other
| NIST CSF Function | MITRE ATT&CK Complement |
|---|---|
| Identify | Threat intelligence mapped to ATT&CK techniques helps identify relevant threats to your organisation |
| Protect | ATT&CK techniques inform which protective controls to prioritise based on likely adversary behaviour |
| Detect | ATT&CK provides specific detection logic and analytics for each technique, enabling measurable detection engineering |
| Respond | ATT&CK helps responders understand adversary TTPs during incidents for more effective containment |
| Recover | Understanding attack techniques informs recovery priorities and hardening against re-compromise |
Practical Application
Use NIST CSF when:
- Building or assessing an organisational security programme
- Communicating security posture to executives and boards
- Meeting regulatory and compliance requirements
- Establishing security governance and risk management
- Planning security investments and resource allocation
Use MITRE ATT&CK when:
- Engineering and validating detections
- Conducting adversary emulation and red teaming
- Performing threat-informed defence assessments
- Mapping threat intelligence to defensive controls
- Measuring detection and response capabilities
Mapping NIST CSF to MITRE ATT&CK for Validation
Organisations can combine both frameworks by using MITRE ATT&CK to validate NIST CSF implementations:
- Identify: Use ATT&CK-informed threat intelligence to prioritise assets and risks
- Protect: Map ATT&CK techniques to protective controls and test coverage
- Detect: Validate detection rules against specific ATT&CK techniques
- Respond: Test incident response playbooks against ATT&CK scenarios
- Recover: Simulate re-compromise scenarios to validate recovery procedures
FourCore ATTACK enables organisations to operationalise MITRE ATT&CK for continuous security validation, providing measurable evidence of NIST CSF control effectiveness through automated adversary simulation.