Cybersecurity Playbook Sharing with STIX 2.1
arXiv:2203.04136
Abstract
Understanding that interoperable security playbooks will become a fundamental component of defenders' arsenal to decrease attack detection and response times, it is time to consider their position in structured sharing efforts. This report documents the process of extending Structured Threat Information eXpression (STIX) version 2.1, using the available extension definition mechanism, to enable sharing security playbooks, including Collaborative Automated Course of Action Operations (CACAO) playbooks.
Cited by in corpus (4)
- A Blueprint for Collaborative Cybersecurity Operations Centres with Capacity for Shared Situational Awareness, Coordinated Response, and Joint Preparedness
- Towards Incident Response Orchestration and Automation for the Advanced Metering Infrastructure
- Operationalizing Cybersecurity Knowledge: Design, Implementation & Evaluation of a Knowledge Management System for CACAO Playbooks
- Reviewing BPMN as a Modeling Notation for CACAO Security Playbooks