Just Released
CIS Controls for Threat Mitigations
CIS Controls for Threat Mitigations connects the security capabilities of the Center for Internet Security’s Critical Security Controls to adversary behaviors documented in MITRE ATT&CK.
The project applies our established mapping methodology to identify in-scope CIS Safeguards, review their security capabilities, evaluate relevant ATT&CK techniques and sub-techniques, and document the rationale for each mapping. Defenders can use the mappings to trace implemented Safeguards to adversary behaviors, identify potential coverage gaps, and inform control design, validation, and testing.