MISP / MISP/cexf

Document exercise objectives and outcomes

Open
#2 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
11
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Document the exercise objectives and outcomes. Something similar as as Table 2 and Table 3 from https://www.mitre.org/sites/default/files/publications/pr_14-3929-cyber-exercise-playbook.pdf

(not exactly sure about the 'how', just including the idea )

ID Objective
01 Determine the effectiveness of the cyber education provided to the training
audience prior to the start of the exercise
02 Assess effectiveness of the organization’s/exercise’s incident reporting and analysis
guides for remedying deficiencies
03 Assess ability of the training audience to detect and properly react to hostile
activity during the exercise
04 Assess the organization’s capability to determine operational impacts of cyber
attacks and implement proper recovery procedures for the exercise
05 Determine the success of scenario planning and execution between the ECG, RT,
and training audience
06 Understand the implications of losing trust in IT systems and capture the workarounds for such losses
07 Expose and correct weaknesses in cyber security systems
08 Expose and correct weaknesses in cyber operations policies and procedures
09 Determine what enhancements or capabilities are needed to protect an information
system and provide for operations in a hostile environment
10 Determine if the injects meet the objectives of the training
11 Enhance cyber awareness, readiness, and coordination
12 Develop contingency plans for surviving the loss of some or all IT systems 

image

image

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the MITRE Cyber Exercise Playbook, especially Tables 2 and 3 and the attached examples, to understand the proposed objectives and outcomes format. Identify the project's documentation location before deciding how to incorporate the material; done means the exercise objectives and outcomes are documented in a clear, agreed format.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.