Glossary · Automation fundamentals, platforms and components
MITRE ATT&CK for ICS
Also known as: ATT&CK for ICS
German: MITRE ATT&CK für ICS
In OT security, MITRE ATT&CK for ICS is a publicly available knowledge base maintained by MITRE that describes tactics and techniques adversaries use against industrial control systems, based on observed attacks.
- Automation components
- OT security
In one sentence
MITRE ATT&CK for ICS is a public knowledge base of tactics and techniques that attackers use against industrial control systems.
Example
The security team maps its OT monitoring rules to ATT&CK for ICS techniques and finds that unauthorized firmware changes are not yet detected.
How it applies
- Engineering: Designers use ATT&CK for ICS to check which attack techniques their architecture and security measures address.
- Operation: Security operations map detections and incidents to techniques, which gives a shared language across tools and teams.
- Documentation: Security documentation and threat models can reference technique IDs to explain which threats a measure addresses. Keep references current, as the knowledge base is updated regularly.
- Security testing: Penetration tests and red team exercises for OT can be planned and reported using ATT&CK for ICS tactics.
ATT&CK for ICS vs. IEC 62443
IEC 62443 defines requirements and processes for securing industrial automation systems. ATT&CK for ICS describes adversary behavior. They complement each other: one says what to build, the other helps test it against real attack patterns. Neither makes a system secure by itself.