Joinable Labs Launches “Joinable Security” Platform to Govern Threat‑Intel Mapping & Automated Response Playbooks
What Happened — Joinable Labs introduced Joinable Security, a two‑product suite comprising a free Joinable Threat Map that normalises public threat reports to the MITRE ATT&CK framework, and Joinable Runbooks, an enterprise tool that converts an organization’s incident‑response documentation into structured, permission‑governed knowledge and drives “agentic” remediation actions.
Why It Matters for Compliance & Audit Readiness
- Continuous‑compliance programs (SOC 2) require documented, repeatable response procedures; Joinable Runbooks creates a single source of truth that can be audited as evidence of control execution.
- Mapping external threat intel to ATT&CK gives a defensible, up‑to‑date risk‑assessment baseline that aligns with the SOC 2 CC6.1 (risk mitigation) and CC7.1 (incident‑response) criteria.
- The platform’s integration with SIEM/SOAR tools enables automated collection of execution logs, supporting the “continuous monitoring” evidence needed for audit readiness.
Who Is Affected
- Technology‑SaaS vendors, MSSPs, and internal security teams across all industries that maintain incident‑response playbooks and need to demonstrate SOC 2 compliance.
Recommended Actions
- Inventory existing IR playbooks and map each step to MITRE ATT&CK techniques.
- Ingest the structured playbooks into a governed knowledge base (e.g., Joinable Runbooks or an equivalent) to generate immutable audit logs of updates and executions.
- Align the mapped techniques with SOC 2 CC6.1/CC7.1 controls and capture execution evidence for continuous‑compliance reporting.
Source: Help Net Security
Technical Notes
- Joinable Threat Map aggregates publicly released threat reports from government agencies and security organisations, auto‑classifying them into ATT&CK tactics/techniques.
- Joinable Runbooks leverages the Propagator “Trusted Knowledge Foundry” to keep response documentation synchronised with source files, and exposes APIs for SIEM/SOAR integration.
Source: Help Net Security