DOE OSTI2020
During the first three phases, the CCE Team identified any instances of unverified trust in the organization’s technologies, processes, and procedures, any or all of which could be used to adversely impact the system. In Phase 4, the primary goal is to remove the possibility of the end effect—that is, to develop means or mechanisms that will ensure an adversary cannot achieve their Objective (identified in Phase 1) via cyber means. Such measures are known as “protections.” In some cases, this may not be possible, or the implementation of protections may not be desirable due to other considerations. In such cases, means and mechanisms should be developed that focus on putting an organization in a better position to identify adversary activities directed against it, increasing the cost of cyber-enabled sabotage for the adversary (including making things more difficult for the adversary and attempting to lower the chances an adversary may succeed), or decreasing the recovery cost of a victim organization. These measures are known as “mitigations.”
99 GENERAL AND MISCELLANEOUS↗