Blog

CIS Controls for Threat Mitigation

CIS Controls for Threat Mitigation

By Tiffany Bergeron, Daniel Bah and Oshien Charly • October 5, 2026

CIS Controls across people, processes, technology, and data

Organizations face threats across people, processes, technology, and data, requiring safeguards that work together across the enterprise. Adversaries routinely exploit weaknesses in how systems are configured, managed, and used, including gaps between technical controls, operational processes, and user activity. Addressing these risks requires security practices that consider not only whether controls are implemented, but also how those controls affect the techniques adversaries use to compromise systems and data.

MITRE’s Center for Threat-Informed Defense (CTID) advances a threat-informed approach that enables organizations to align security capabilities with known adversary behaviors. By connecting security controls to adversary tradecraft - or creating mappings - defenders can better understand defensive coverage, identify gaps, prioritize security investments, and assess how existing safeguards address the techniques adversaries use.

The Center for Internet Security Critical Security Controls (CIS Controls) are a prescriptive, prioritized, and simplified set of best practices designed to help organizations strengthen their defenses. Cybersecurity practitioners around the world use the CIS Controls to reduce exposure to common threats and establish a practical foundation for protecting systems, networks, and data.

We partnered with CTID members including Center for Internet Security, Citigroup, CrowdStrike, HCA Healthcare, JPMorganChase, Lloyds Banking Group, and Verizon Business to map the CIS Controls to adversary behaviors documented in MITRE ATT&CK®. Cyber defenders now have easy access to explore mapped CIS-based security capabilities from the perspective of the ATT&CK techniques they mitigate to enhance the design and implementation of a threat-informed operational cybersecurity program.

The CIS Control mapping resources - including the mappings themselves, ATT&CK Navigator layers, and the mapping methodology - are all available on our Mappings Explorer website.

Our Approach

We followed our established methodology to connect security capabilities in the CIS Controls to relevant ATT&CK techniques and sub-techniques. Developed through our experience in mapping multiple security frameworks, this methodology provides a repeatable way to use ATT&CK to understand how security capabilities mitigate adversary behavior.

The methodology is iterative and consists of four main steps, shown in the diagram below. Each step builds on the previous one, allowing analysts to understand a control’s mitigating capabilities and then map those capabilities to relevant ATT&CK techniques and sub-techniques.

CTID Mapping Methodology
CTID Mapping Methodology

The first step identifies the security capabilities in scope. For this effort, we moved from the CIS Control level to the individual CIS Safeguards, which provide the specific implementation actions needed to evaluate a meaningful relationship with ATT&CK. This distinction was important because a single CIS Control may contain Safeguards that use different defensive mechanisms and address different adversary behaviors. Safeguards considered in-scope:

  • Result in a technical or operational security capability with a direct effect on systems, applications, networks, identities, or data.

  • Prevent, restrict, detect, or otherwise affect the execution of adversary techniques.

  • Can be implemented or enforced through a defined technical mechanism, rather than relying primarily on policy, governance, or administrative process.

Each in-scope Safeguard and its supporting documentation is then reviewed to understand what it does in practice. The Safeguard’s security functions and capabilities are identified, such as access control or data protection, and any documented threats or adversary behaviors it is intended to mitigate are noted.

Next, each Safeguard is assessed in the context of relevant ATT&CK mitigations to identify candidate ATT&CK techniques and sub-techniques for mapping. A Safeguard may not provide mitigation of every technique associated with related ATT&CK mitigations, and as such, each candidate is evaluated individually to determine whether the capability’s specific security functions and capabilities can meaningfully prevent or disrupt the defined adversary behavior.

Validated relationships are documented as self-contained mappings. Each mapping comment provides rationale for the relationship and describes the specific security functions and capabilities provided by the Safeguard that could directly mitigate an adversary’s ability to execute the behavior described by the ATT&CK (sub-)technique.

The Results

Using this methodology, we mapped the Safeguards contained in CIS Controls v8.1 to ATT&CK v19.1 techniques and sub-techniques. More than 70 CIS Safeguards across the 18 CIS Controls were identified as providing in-scope defensive capabilities, spanning areas such as Secure Configuration of Enterprise Assets and Software, Network Monitoring and Defense, and Access Control Management.

The analysis produced more than 1,200 mapping relationships between CIS Safeguards and ATT&CK techniques and sub-techniques. Each relationship represents a case where the security functions and capabilities provided by the Safeguard can prevent or disrupt an adversary’s ability to perform the mapped behavior.

Example Mappings

The image below demonstrates how CIS Control 9, Email and Web Browser Protections, includes Safeguards that can help defend against different types of email-based attacks:

Examples of CIS Control 9: Email and Web Browser Protections
Examples of CIS Control 9: Email and Web Browser Protections

These example mappings demonstrate how different CIS Safeguards can mitigate different email-based adversary behaviors: impersonating a trusted sender, delivering a malicious attachment, or directing users to malicious destinations. Depending on the attack, one or more of these Safeguards can provide defensive measures. The mapping comments provided in each mapping describe the specific security capability supporting each relationship and any conditions under which that relationship applies.

  • Safeguard 9.5, Implement DMARC, maps to Email Spoofing (T1684.002). DMARC, together with SPF and DKIM, can help identify and filter messages that improperly impersonate trusted domains.

  • Safeguard 9.6, Block Unnecessary File Types, maps to Spearphishing Attachment (T1566.001) by preventing unnecessary or high-risk attachment types from entering the enterprise through the email gateway.

  • Safeguard 9.3, Maintain and Enforce Network-Based URL Filters, maps to Spearphishing Link (T1566.002) by restricting access to potentially malicious or unapproved destinations.

Using the Mappings

These mappings help organizations use the CIS Controls with a threat-informed approach. The mappings provide a structured, evidence-based connection between CIS Safeguards and ATT&CK (sub-)techniques, helping organizations translate traditional security control implementation into a clearer understanding of defensive coverage against documented adversary behavior. For example, defenders can:

  • Trace implemented CIS Safeguards to the ATT&CK techniques and sub-techniques they address

  • Understand how existing CIS-based defenses align with adversary behaviors documented in ATT&CK

  • Identify potential gaps in defensive coverage and examine techniques that can be addressed by specific Safeguard implementation

  • Reference relevant ATT&CK techniques when designing, validating, or testing CIS-based security control implementation

  • Apply a structured, threat-informed foundation to support gap analysis, threat modeling, or security assessments

The Examples of CIS Control 9: Email and Web Browser Protections image above presents examples that connect different email-based attacks with CIS Safeguards that may help defend against them as well as the associated MITRE ATT&CK adversary behaviors. These examples show, at a very basic level, how defenders can use the mappings to understand how existing CIS-based defenses align to ATT&CK techniques, assess whether the mapped Safeguards are implemented in their environments, and identify potential defensive coverage gaps.

Get Involved

We welcome your feedback and contributions:

  • Review the mappings, use them, and tell us what you think. We welcome your review and feedback on the CIS Control mappings, our methodology, and resources.

  • Help us prioritize additional platforms to map. Let us know what platforms you would like to see mapped to ATT&CK. Your input will help us prioritize how we expand our mappings.

  • Share your ideas. Share your ideas or suggestions for additional tools and resources for helping the community to understand and make threat-informed decisions.

You are also welcome to submit issues for any technical questions/concerns or contact us directly for more general inquiries.


© 2026 The MITRE Corporation. Approved for Public Release. ALL RIGHTS RESERVED. Document number .


About the Authors

Tiffany Bergeron

As Chief Mappings Architect, Tiffany leads the Center's MITRE ATT&CK mapping initiatives, including Mappings Explorer, security control framework mappings, and the Mappings Editor. Her work advances threat-informed defense through practical tools, research, and guidance that help organizations understand real-world adversary threats and align effective defensive measures. She specializes in threat intelligence, adversary behavior analysis, and actionable mitigations, with experience spanning the Department of Defense, Department of Homeland Security, and private industry.

More by Tiffany Bergeron
Daniel Bah

As a Senior Cybersecurity Engineer at MITRE, Daniel Bah supports various defensive security operations and research efforts with a focus on ATT&CK-informed SOC assessments, CTID ATT&CK mappings, and partner nation cyber capacity building.

More by Daniel Bah

Recent Blog Posts:

CIS Controls for Threat Mitigation

Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security …

Continue reading

Putting Detection Coverage to the Test: A Windows Security Case Study

A case study of 144 Sigma analytics using Windows Security log sources shows why ATT&CK mappings alone do not reveal the depth or quality of …

Continue reading

Beyond the Heatmap: A New Way to Measure Detection Coverage

Summiting the Pyramid introduces implementation coverage and detection quality to help defenders measure the depth and effectiveness of detection …

Continue reading