Zero Trust Architecture: ISO vs. MITRE ATTACK

A couple of months ago, I released a comprehensive framework stack combining NIST 800-53 and MITRE ATTACK with Zero Trust to provide a complete view of the relevant controls and attack techniques within each Zero Trust pillar.

Here’s the original article if you missed it: Zero Trust Architecture: NIST vs. MITRE ATTACK

The feedback was overwhelming, sparking some great conversations in these areas. One interesting request was for an ISO version of this mapping, which I enjoyed working on.

So, for my friends across EMEA and beyond, I’ve just finished a second version of this visual framework mapping using ISO 27001 against MITRE ATTACK.

This version has updated attack techniques for each zero-trust pillar.

ISO x MITRE x Zero Trust

By capturing the ISO controls against attack techniques in this way, we get the following:

  • A clear, integrated view of how ISO 27001 and MITRE ATT&CK can align to zero trust architecture (ZTA) principals.

  • Allow organisations to quickly identify any compliance gaps in their security posture.

  • Highlight which specific threats each zero trust pillar addresses (and faces).

  • Demonstrate how globally recognised security compliance standards can align with zero trust implementations.

My biggest takeaway from working on both projects is that combining attack and defence frameworks with modern architecture practices like Zero Trust provides greater depth and a complete view of the critical security domains within an organisation. 

Visualising this creates a well-structured and innovative guide to strengthening your security posture and achieving security compliance at the same time.

Previous
Previous

Proactive Threat Defence: Know(ing) Your D.N.A

Next
Next

Cyber Threat Knowledge vs. Cyber Threat Action