CIS Controls for Threat Mitigations
CIS Controls for Threat Mitigations connects the security capabilities of the Center for Internet Security’s Critical Security Controls to …
October 5, 2026
CIS Controls for Threat Mitigations connects the security capabilities of the Center for Internet Security’s Critical Security Controls to adversary behaviors documented in MITRE ATT&CK.
The project applies our established mapping methodology to identify in-scope CIS Safeguards, review their security capabilities, evaluate relevant ATT&CK techniques and sub-techniques, and document the rationale for each mapping. Defenders can use the mappings to trace implemented Safeguards to adversary behaviors, identify potential coverage gaps, and inform control design, validation, and testing.
The CIS Controls mappings are part of our Mappings Explorer program. Use the Mappings Explorer website to navigate, explore, search, and download our mappings of security capabilities to MITRE ATT&CK®.
Implementing security controls does not by itself explain how those controls address the techniques adversaries use to compromise systems and data.
Map the technical and operational capabilities of CIS Safeguards to MITRE ATT&CK techniques and sub-techniques, with documented rationale for each relationship.
Defenders can assess CIS-based defensive coverage, identify potential gaps, and use adversary behavior to guide control design, validation, and testing.
CIS Controls for Threat Mitigations connects the security capabilities of the Center for Internet Security’s Critical Security Controls to …
Summiting the Pyramid helps defenders measure the depth and quality of detection coverage beyond an ATT&CK heatmap. This release introduces …
Attack Flow helps defenders capture the entire scope of a cyber attack and communicate what matters. By representing actions, conditions, and …
Sign up for our "Stay Informed" mailing list to receive announcements for project publications, upcoming events, and other news about the Center.