Breaking: CISA Releases Analysis of FY20 Risk and Vulnerability Assessments

Jul 8, 2021

Original release date: July 8, 2021

CISA has released an analysis and infographic detailing the findings from the Risk and Vulnerability Assessments (RVAs) conducted in Fiscal Year (FY) 2020 across multiple sectors.

The analysis details a sample attack path a cyber threat actor could take to compromise an organization with weaknesses that are representative of those CISA observed in FY20 RVAs. The infographic provides a high-level snapshot of five potential attack paths and breaks out the most successful techniques for each tactic that the RVAs documented. Both the analysis and the infographic map threat actor behavior to the MITRE ATT&CK® framework.

Full Document here – FY20_RVAs_Mapped_to_the_MITRE_ATTCK_Framework_508