CIS Controls for Threat Mitigation
Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security …
By Tiffany Bergeron, Daniel Bah and Oshien Charly • October 5, 2026
Organizations face threats across people, processes, technology, and data, requiring safeguards that work together across the enterprise. Adversaries routinely exploit weaknesses in how systems are configured, managed, and used, including gaps between technical controls, operational processes, and user activity. Addressing these risks requires security practices that consider not only whether controls are implemented, but also how those controls affect the techniques adversaries use to compromise systems and data.
MITRE’s Center for Threat-Informed Defense (CTID) advances a threat-informed approach that enables organizations to align security capabilities with known adversary behaviors. By connecting security controls to adversary tradecraft - or creating mappings - defenders can better understand defensive coverage, identify gaps, prioritize security investments, and assess how existing safeguards address the techniques adversaries use.
The Center for Internet Security Critical Security Controls (CIS Controls) are a prescriptive, prioritized, and simplified set of best practices designed to help organizations strengthen their defenses. Cybersecurity practitioners around the world use the CIS Controls to reduce exposure to common threats and establish a practical foundation for protecting systems, networks, and data.
We partnered with CTID members including Center for Internet Security, Citigroup, CrowdStrike, HCA Healthcare, JPMorganChase, Lloyds Banking Group, and Verizon Business to map the CIS Controls to adversary behaviors documented in MITRE ATT&CK®. Cyber defenders now have easy access to explore mapped CIS-based security capabilities from the perspective of the ATT&CK techniques they mitigate to enhance the design and implementation of a threat-informed operational cybersecurity program.
The CIS Control mapping resources - including the mappings themselves, ATT&CK Navigator layers, and the mapping methodology - are all available on our Mappings Explorer website.
We followed our established methodology to connect security capabilities in the CIS Controls to relevant ATT&CK techniques and sub-techniques. Developed through our experience in mapping multiple security frameworks, this methodology provides a repeatable way to use ATT&CK to understand how security capabilities mitigate adversary behavior.
The methodology is iterative and consists of four main steps, shown in the diagram below. Each step builds on the previous one, allowing analysts to understand a control’s mitigating capabilities and then map those capabilities to relevant ATT&CK techniques and sub-techniques.
The first step identifies the security capabilities in scope. For this effort, we moved from the CIS Control level to the individual CIS Safeguards, which provide the specific implementation actions needed to evaluate a meaningful relationship with ATT&CK. This distinction was important because a single CIS Control may contain Safeguards that use different defensive mechanisms and address different adversary behaviors. Safeguards considered in-scope:
Result in a technical or operational security capability with a direct effect on systems, applications, networks, identities, or data.
Prevent, restrict, detect, or otherwise affect the execution of adversary techniques.
Can be implemented or enforced through a defined technical mechanism, rather than relying primarily on policy, governance, or administrative process.
Each in-scope Safeguard and its supporting documentation is then reviewed to understand what it does in practice. The Safeguard’s security functions and capabilities are identified, such as access control or data protection, and any documented threats or adversary behaviors it is intended to mitigate are noted.
Next, each Safeguard is assessed in the context of relevant ATT&CK mitigations to identify candidate ATT&CK techniques and sub-techniques for mapping. A Safeguard may not provide mitigation of every technique associated with related ATT&CK mitigations, and as such, each candidate is evaluated individually to determine whether the capability’s specific security functions and capabilities can meaningfully prevent or disrupt the defined adversary behavior.
Validated relationships are documented as self-contained mappings. Each mapping comment provides rationale for the relationship and describes the specific security functions and capabilities provided by the Safeguard that could directly mitigate an adversary’s ability to execute the behavior described by the ATT&CK (sub-)technique.
Using this methodology, we mapped the Safeguards contained in CIS Controls v8.1 to ATT&CK v19.1 techniques and sub-techniques. More than 70 CIS Safeguards across the 18 CIS Controls were identified as providing in-scope defensive capabilities, spanning areas such as Secure Configuration of Enterprise Assets and Software, Network Monitoring and Defense, and Access Control Management.
The analysis produced more than 1,200 mapping relationships between CIS Safeguards and ATT&CK techniques and sub-techniques. Each relationship represents a case where the security functions and capabilities provided by the Safeguard can prevent or disrupt an adversary’s ability to perform the mapped behavior.
The image below demonstrates how CIS Control 9, Email and Web Browser Protections, includes Safeguards that can help defend against different types of email-based attacks:
These example mappings demonstrate how different CIS Safeguards can mitigate different email-based adversary behaviors: impersonating a trusted sender, delivering a malicious attachment, or directing users to malicious destinations. Depending on the attack, one or more of these Safeguards can provide defensive measures. The mapping comments provided in each mapping describe the specific security capability supporting each relationship and any conditions under which that relationship applies.
Safeguard 9.5, Implement DMARC, maps to Email Spoofing (T1684.002). DMARC, together with SPF and DKIM, can help identify and filter messages that improperly impersonate trusted domains.
Safeguard 9.6, Block Unnecessary File Types, maps to Spearphishing Attachment (T1566.001) by preventing unnecessary or high-risk attachment types from entering the enterprise through the email gateway.
Safeguard 9.3, Maintain and Enforce Network-Based URL Filters, maps to Spearphishing Link (T1566.002) by restricting access to potentially malicious or unapproved destinations.
These mappings help organizations use the CIS Controls with a threat-informed approach. The mappings provide a structured, evidence-based connection between CIS Safeguards and ATT&CK (sub-)techniques, helping organizations translate traditional security control implementation into a clearer understanding of defensive coverage against documented adversary behavior. For example, defenders can:
Trace implemented CIS Safeguards to the ATT&CK techniques and sub-techniques they address
Understand how existing CIS-based defenses align with adversary behaviors documented in ATT&CK
Identify potential gaps in defensive coverage and examine techniques that can be addressed by specific Safeguard implementation
Reference relevant ATT&CK techniques when designing, validating, or testing CIS-based security control implementation
Apply a structured, threat-informed foundation to support gap analysis, threat modeling, or security assessments
The Examples of CIS Control 9: Email and Web Browser Protections image above presents examples that connect different email-based attacks with CIS Safeguards that may help defend against them as well as the associated MITRE ATT&CK adversary behaviors. These examples show, at a very basic level, how defenders can use the mappings to understand how existing CIS-based defenses align to ATT&CK techniques, assess whether the mapped Safeguards are implemented in their environments, and identify potential defensive coverage gaps.
We welcome your feedback and contributions:
Review the mappings, use them, and tell us what you think. We welcome your review and feedback on the CIS Control mappings, our methodology, and resources.
Help us prioritize additional platforms to map. Let us know what platforms you would like to see mapped to ATT&CK. Your input will help us prioritize how we expand our mappings.
Share your ideas. Share your ideas or suggestions for additional tools and resources for helping the community to understand and make threat-informed decisions.
You are also welcome to submit issues for any technical questions/concerns or contact us directly for more general inquiries.
© 2026 The MITRE Corporation. Approved for Public Release. ALL RIGHTS RESERVED. Document number
.
Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security …
A case study of 144 Sigma analytics using Windows Security log sources shows why ATT&CK mappings alone do not reveal the depth or quality of …
Summiting the Pyramid introduces implementation coverage and detection quality to help defenders measure the depth and effectiveness of detection …