MAPPING FRAMEWORKS
CRI Profile
The CRI Profile is a control framework to develop and assess cybersecurity and resiliency programs, produced by and for the global financial sector and maintained by the Cyber Risk Institute (CRI). These mappings connect the security capability coverage of the CRI Profile's Diagnostic Statements with threat mitigation of real-world adversarial behaviors as described in MITRE ATT&CK. The connection of ATT&CK with the CRI Profile control program framework empowers threat-informed analysis and decision-making for cybersecurity control program design and implementation by the financial services sector.
ATT&CK Version 16.1 ATT&CK Domain Enterprise
Learn MoreIntel vPro
Advanced security features in Intel vPro hardware can be leveraged by operating system (OS) and security software features across system attack surfaces to optimize mitigations against cyber threats. These mappings demonstrate the practical application of hardware features by capabilities in Microsoft Windows 11 with Defender and CrowdStrike Falcon to assist defenders in understanding how these integrated capabilities can help mitigate real-world adversary behaviors as described in MITRE ATT&CK®.
ATT&CK Version 15.1 ATT&CK Domain Enterprise
Learn MoreNIST 800-53
National Institute of Standards in Technology (NIST) Special Publication 800-53 provides a catalog of security and privacy controls for the protection of information systems and organizations from a diverse set of threats and risks. These mappings provide resources for assessing security control coverage of real-world threats as described in the MITRE ATT&CK® knowledge base and provide a foundation for integrating ATT&CK-based threat intelligence into the risk management process. Shared understanding of how the implementation of NIST 800-53 security controls in an environment can mitigate adversary techniques of interest is an important step to bring security operations teams and risk management teams together to build a structured, threat-informed approach to securing systems and environments.
ATT&CK Versions 16.1, 14.1, 12.1, 10.1, 9.0, 8.2 ATT&CK Domain Enterprise
Learn MoreKnown Exploited Vulnerabilities
The Known Exploited Vulnerabilities (KEV) Catalog is an authoritative source of vulnerabilities exploited in the wild maintained by the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA). Vulnerabilities in the KEV Catalog are contained in the Common Vulnerabilities and Exposures (CVE®) List, which identifies and defines publicly known cybersecurity vulnerabilities. These mappings use the behaviors described in MITRE ATT&CK® to connect known exploited CVEs to publicly reported methods and impacts of adversary exploitation. Mapped ATT&CK techniques enable defenders to take a threat-informed approach to vulnerability management. With knowledge of mapped adversary behaviors, defenders will better understand how a vulnerability can impact them, helping defenders integrate vulnerability information into their risk models and identify appropriate compensating security controls.
ATT&CK Versions 16.1, 15.1 ATT&CK Domains Enterprise, Mobile
Learn MoreVERIS
The Vocabulary for Event Recording and Incident Sharing (VERIS) provides a common language for describing security incidents in a structured and repeatable manner that allows for the analysis of data across a variety of incidents. These mappings provide the context to better connect the who, what, and why captured in VERIS incident representation with the when and how described in MITRE ATT&CK® adversary behavioral tactics, techniques, and procedures (TTPs). This connection empowers defenders with the ability to efficiently connect adversary TTPs to their real-world impact, and facilitates the linkage of ATT&CK-based threat intelligence with VERIS-based incident reports for more actionable insights.
ATT&CK Versions 16.1, 12.1, 9.0 ATT&CK Domains Enterprise, ICS, Mobile
Learn MoreAzure
Microsoft Azure is a widely used cloud computing platform provided by Microsoft. Azure offers a range of security capabilities to protect cloud data, applications, and infrastructure from threats. These mappings connect Azure security capabilities to adversary behaviors in MITRE ATT&CK®, providing Azure users with a comprehensive view of how native Azure security capabilities can be used to prevent, detect, and respond to prevalent cloud threats. As a result, Azure users can evaluate the effectiveness of native security controls against specific ATT&CK techniques and take a threat-informed approach to understand, prioritize, and mitigate adversary behaviors that are most important for their environment.
ATT&CK Versions 16.1, 8.2 ATT&CK Domain Enterprise
Learn MoreGCP
Google Cloud Platform (GCP) is a widely used cloud computing platform provided by Google. GCP offers a range of security capabilities to protect cloud data, applications, and infrastructure from threats. These mappings connect GCP security capabilities to adversary behaviors in MITRE ATT&CK®, providing GCP users with a comprehensive view of how native GCP security capabilities can be used to prevent, detect, and respond to prevalent cloud threats. As a result, GCP users can evaluate the effectiveness of native security controls against specific ATT&CK techniques and take a threat-informed approach to understand, prioritize, and mitigate adversary behaviors that are most important for their environment.
ATT&CK Versions 16.1, 10.0 ATT&CK Domain Enterprise
Learn MoreAWS
Amazon Web Services (AWS) is a widely used cloud computing platform provided by Amazon. AWS offers a range of security capabilities to protect cloud data, applications, and infrastructure from threats. These mappings connect AWS security capabilities to adversary behaviors in MITRE ATT&CK®, providing AWS users with a comprehensive view of how native AWS security capabilities can be used to prevent, detect, and respond to prevalent cloud threats. As a result, AWS users can evaluate the effectiveness of native security controls against specific ATT&CK techniques and take a threat-informed approach to understand, prioritize, and mitigate adversary behaviors that are most important for their environment.
ATT&CK Versions 16.1, 9.0 ATT&CK Domain Enterprise
Learn MoreM365
Microsoft 365 (M365) is a widely used Software as a Service (SaaS) product family of productivity software, collaboration, and cloud-based services. These mappings connect the security controls native to M365 product areas to MITRE ATT&CK® providing resources to assess how to protect, detect, and respond to real-world threats as described in the ATT&CK knowledge base. As a result, M365 users can evaluate the effectiveness of native security controls against specific ATT&CK techniques and take a threat-informed approach to understand, prioritize, and mitigate adversary behaviors that are most important for their environment.
ATT&CK Versions 16.1, 14.1 ATT&CK Domain Enterprise
Learn More 
