ASOM-Fedv6.1Open the explorer
M9.08 · M9 Spoiling Attack · 8 of 9

Workforce Threat Briefing

What It Does

Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.

Observable indicator. Briefings cite current campaigns and reach the roles those campaigns target.

Where It Sits

A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.

  • Form of maneuverM9 Spoiling AttackDisrupt adversary staging before the attack is launched.
  • Terrain layerT7 WorkforceTerrain that is also the force. Key terrain: Privileged humans, the roles that can approve a change, the separation pipeline.
  • Position in the form8 of 9M9 carries 9 cataloged techniques; this is the 8th in catalog order.

Phases It Is Employed In

Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.

  • Phase 0ShapeContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
  • Phase IDeterVisible hardening, a deception grid, and a stated attribution posture.

Controls That Assess It

The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.

  • WF-3 Role-Based ReadinessWorkforce TerrainTo prepare people for the attacks their role attracts, and to know whether the preparation worked.
  • CE-2 Priority Intelligence RequirementsCycle Execution and AssuranceTo direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.

In MITRE D3FEND

Workforce Threat Briefing — a human preparation activity.

Related Techniques

The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.

Assessed Alongside

Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 29 that share at least one control.