About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Staff and Partners Site Map
  Home > Our Work > Mission Areas > Cybersecurity >

Cybersecurity -- Strengthening Cyber Defense
   
Home
About
Leadership
Thinking
Forward
Contact Us
Focus Areas
Situation
Awareness
Resiliency
Threat-Based
Defense
Partnership
Innovation
Blog:
Cyber Depot
Resource
Center
Research
Standards
Tools
Awareness
& Training
Library
Learn more about MITRE's free mobile app

Cyber Standards

Consider how much we rely on standards in our daily lives. When you plug in a power cord in the U.S., for example, you can reliably count on the plug and socket to match, regardless of manufacturer, regardless of location. Towards this same end, MITRE is collaborating with industry and Government to develop common approaches that enable a collective response to ever-changing cyber threats.

At MITRE, our focus has been to develop and expand the use of common terminology and structures to allow for collaboration and communication across the cybersecurity community. These efforts include providing registries of baseline security data, establishing standardized languages as a means for accurately communicating cybersecurity information, defining proper usage of cybersecurity concepts, and helping support community approaches for commonly accepted cybersecurity processes.

One of our earliest attempts to systematically name security vulnerabilities was the Common Vulnerabilities and Exposures (CVE®) list, which enables correlation among security products, services, and organizations. CVE is recognized as the standard for naming vulnerabilities, and well over 100 products and services from more than 75 vendors have achieved CVE compatibility. Under DHS sponsorship and in collaboration with the CVE Editorial Board, MITRE works as the independent third party to advance CVE, maintain the CVE List, and ensure that CVE serves the public interest.

MITRE is also working on two new initiatives for sharing cyber threat information: the Trusted Automated eXchange of Indicator Information (TAXII™) and the Structured Threat Information eXpression (STIX™), sponsored by the Department of Homeland Security. TAXII defines a set of protocols for securely exchanging cyber threat information for the detection, prevention and mitigation of cyber threats in real time. STIX provides a common format for cyber threat information, including cyber observables, indicators of compromise, incidents, TTPs (techniques, tactics, and procedures), and campaigns. Together, TAXII and STIX will enable threat-sharing communities to exchange actionable, structured threat intelligence to promote collective defense.

We are continuing to collaborate in similar community efforts surrounding vulnerability management, software assurance, application security, asset management, enterprise reporting, malware protection, configuration management, event management, remediation, and threat information sharing. These efforts include:

Cybersecurity Registries

Cybersecurity Languages/Formats & Protocols

Learn more by visiting MITRE's Making Security Measurable website.

Featured Items



 
Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development
 
 
 

Solutions That Make a Difference.®
Copyright © 1997-2013, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

IDG's Computerworld Names MITRE a "Best Place to Work in IT" for Eighth Straight Year The Boston Globe Ranks MITRE Number 6 Top Place to Work Fast Company Names MITRE One of the "World's 50 Most Innovative Companies"
 

Privacy Policy | Contact Us