INFORM 2026: MITRE’s Updated Threat-Informed Defense Maturity Model Explained
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。好的,我先仔细读一下这篇文章。 这篇文章主要讲的是MITRE的CTID中心在1月8日更新了INFORM模型,这是一个威胁知情防御成熟度模型。更新是基于两年的使用经验和社区反馈,由MITRE、AttackIQ和其他成员合作完成。INFORM帮助组织衡量和提升他们的威胁防御能力,分为三个维度,并且有新的问题和评分机制。还有映射到其他成熟度模型的功能,以及一些实际的应用案例。 用户的需求是用中文总结,控制在100字以内。我需要抓住关键点:更新发布、更新内容、INFORM的作用、新增功能和应用案例。 可能的结构是:MITRE发布更新后的INFORM模型,基于两年经验;帮助组织衡量和提升威胁防御;新增问题、评分和映射功能;广泛应用于资源分配、预算等场景。 现在把这些点浓缩到100字以内: MITRE发布更新后的INFORM模型,整合两年经验和社区反馈;该模型帮助组织衡量和提升威胁防御能力;新增问题、评分机制及与其他模型的映射功能;广泛应用于资源分配、预算等场景。 检查一下字数是否符合要求,并确保没有使用禁止的开头。 </think> MITRE发布更新后的INFORM模型,整合两年经验和社区反馈;该模型帮助组织衡量和提升威胁防御能力;新增问题、评分机制及与其他模型的映射功能;广泛应用于资源分配、预算等场景。 2026-1-9 14:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Avatar photo

On January 8th, MITRE’s Center for Threat-Informed Defense (CTID) published a significant update update to INFORM, its threat-informed defense maturity model. This update reflects the joint efforts of MITRE researchers, AttackIQ, and several CTID members to enhance INFORM based on two years of operational use and broad security community feedback.

“Threat-informed defense is the systematic application of a deep understanding of adversary tradecraft and technology to improve defenses.” – MITRE Center for Threat-Informed Defense

Threat-informed defense (TID) is a continuous process driven by changing IT environments, evolving threats, and ongoing security operations. TID focuses organizations on understanding real-world adversary behaviors, implementing effective defenses against those threats, and validating the efficacy of those defenses. TID applies broadly to organizations regardless of their size, budget, sophistication, or sector. TID aims to make cyber defense more efficient and effective for all.

How INFORM Helps Organizations Mature TID

INFORM guides organizations through adopting and advancing TID as a practice. An INFORM assessment provides a simple means for organizations to:

  • Measure how effectively they apply TID
  • Optimize their security program based on TID principles
  • Visualize their progress over time

INFORM turns TID into something you can measure and continually improve. INFORM will help you baseline your security posture, prioritize investment, and measure improvement against real-world threats.

Making Threat-Informed Defense Measurable

INFORM breaks TID down into three dimensions. Each dimension has a set of measurable components. Dimensions and components are assigned weights to support TID measurement and analysis.

The INFORM web application codifies this maturity model and allows security organizations to quickly and easily conduct an assessment. Assessment results can be saved, and progress can be measured over time.

Originally launched as M3TID in April 2024, INFORM is now widely used by security organizations to understand and advance TID principles. Due to its broad and pragmatic approach, INFORM enables several practical use cases:

Resource Prioritization

INFORM allows organizations to look broadly at their security program and focus resources in the areas that will have the greatest effect in maturing their defenses.

Budget Justification

Organizations use INFORM to justify budget requests by demonstrating how additional resources will contribute to overall TID maturity.

New Client Onboarding

Security providers use INFORM to quickly baseline client maturity and tailor services to client needs.

Supply Chain Analysis

Organizations use INFORM assessments to quickly understand supply chain maturity and prioritize action.  

Team Training

Throughout 2025, MITRE used INFORM as a framework for community-wide TID training and education, empowering students to become TID champions within their organizations.

Large-Scale Surveys

INFORM has been used as the basis of country-wide TID surveys to understand, at a national scale, TID maturity and advise on measurable improvement.

What’s New in INFORM

Two years of operational use and broad security community feedback led to refinement and significant new capability in INFORM.

Revised Questions & Scoring

INFORM components and their questions have been overhauled. The original questions were a bit too focused on MITRE ATT&CK® as an end rather than a means to an end. The original model was a bit too rigid in forcing five components per dimension. New questions add a timeliness factor to the assessment, and the overall scoring algorithm and weights of dimension and components are refined.  

Recommendations Based on Complexity & Impact

Guiding teams with actionable recommendations is supported with a new impact vs. complexity matrix. Each INFORM component is assigned an impact and implementation complexity value allowing the assessment tool to dynamically build a matrix tailored to each organization’s assessment.

Mapped to Other Maturity Models

The INFORM maturity model is now mapped to the CTI Maturity Model, the Red Team Maturity Model, the SOC Maturity Model, and Gartner’s CTEM. These mappings help organizations understand how TID maturity contributes to other more specialized maturity models.

Operationalizing INFORM to Improve Cyber Defense

AttackIQ has supported the development of INFORM since its inception because organizations need a simple approach to learn, adopt, and advance TID. TID should be accessible to all organizations regardless of their size, budget, or sophistication. With this update to INFORM, we are launching new capability and services to guide organizations in systematically adopting and advancing TID.

MITRE’s INFORM maturity model has become the foundation for how we support our customers and partners on their TID journey. You can learn more about INFORM at AttackIQ.

Join us on January 20, 2026 at 10:00 AM PT / 1:00 PM ET for a special session, Threat-INFORM Your Defenses, featuring Jonathan Baker (AttackIQ), Mike Cunningham (MITRE CTID), and Douglas Santos (Fortinet). This session offers an inside look at what’s new in INFORM, how organizations are applying the model in real security programs, and practical guidance for getting started with a threat-informed defense assessment. Eligible attendees may also earn 0.75 ISC2 CPE credit. Register here.

Looking Ahead

We will follow up with an additional blog focused on INFORM, TID, and Gartner CTEM. TID and CTEM together provide a foundation of observed adversary behavior and the programmatic approach to reducing exposures that matter most, optimizing cyber defense operations and reducing risk.

*** This is a Security Bloggers Network syndicated blog from AttackIQ authored by Jon Baker. Read the original post at: https://www.attackiq.com/2026/01/09/inform-2026-mitres-updated-threat-informed-defense-maturity-model-explained/

Avatar photo

Jon Baker

Jon Baker, Vice President Threat-Informed Defense at AttackIQ, leads efforts to accelerate the adoption of threat-informed defense, guiding customers with both services and technology to improve security outcomes. Before joining AttackIQ, Jon joined AttackIQ following a 23-year career at MITRE, where he began as a software engineer and advanced into leadership roles spanning standards development, cyber threat intelligence, and adversary emulation. He created and led MITRE’s cyber threat intelligence and adversary emulation department, overseeing the ATT&CK® Evaluations program and CALDERA™, MITRE’s open-source adversary emulation platform. Most notably, Baker co-founded and directed the MITRE Center for Threat-Informed Defense (CTID), building it into a global collaborative research and development hub that has advanced threat-informed defense practices across the security industry.

jon-baker has 3 posts and counting.See all posts by jon-baker


文章来源: https://securityboulevard.com/2026/01/inform-2026-mitres-updated-threat-informed-defense-maturity-model-explained/
如有侵权请联系:admin#unsafe.sh