A comprehensive method for identifying and prioritizing information security threats based on the integration of the MITRE ATT&CK and DREAD frameworks and the methodology of the FSTEC of Russia
The authors propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks, including the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model.