14 frameworks127 controls

CROSSWALKFramework crosswalk

14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.

Cells coloured by Jaccard similarity of technique sets.

01
DORAISO 27001PCI DSS v4CIS v8NIS2OWASP API Top 10OWASP LLM Top 10OWASP Top 10ISO 27701EU AI ActGDPRNIST CSFEU CRATIBER-EU
DORA
0.400.360.480.540.230.310.330.290.260.450.460.19
ISO 270010.40
0.330.530.440.300.290.340.280.250.400.360.14
PCI DSS v40.360.33
0.410.410.330.350.330.390.400.300.330.29
CIS v80.480.530.41
0.540.330.330.390.290.300.510.480.19
NIS20.540.440.410.54
0.330.360.320.320.270.450.470.22
OWASP API Top 100.230.300.330.330.33
0.360.350.260.200.250.310.11
OWASP LLM Top 100.310.290.350.330.360.36
0.390.390.310.370.390.21
OWASP Top 100.330.340.330.390.320.350.39
0.280.270.310.350.17
ISO 277010.290.280.390.290.320.260.390.28
0.300.380.260.29
EU AI Act0.260.250.400.300.270.200.310.270.30
0.400.310.27
GDPR0.450.400.300.510.450.250.370.310.380.40
0.440.21
NIST CSF0.460.360.330.480.470.310.390.350.260.310.44
0.18
EU CRA
TIBER-EU0.190.140.290.190.220.110.210.170.290.270.210.18

NIST CSFISO 27001 35 shared techniques

Clear ✕
Control AControl BSharedExamples
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.5.7
Threat intelligence
12T1190, T1566, T1059, T1547
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.16
Monitoring activities
11T1059, T1547, T1068, T1070
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.21
Security of network services
10T1078, T1133, T1068, T1070.004
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.25
Secure development life cycle
10T1133, T1547.001, T1068, T1055
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.9
Configuration management
9T1133, T1547.001, T1068, T1003
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.8
Management of technical vulnerabilities
9T1190, T1059, T1068, T1027
RESPOND
RESPOND (RS) — Take action regarding a detected…
A.8.9
Configuration management
9T1190, T1068, T1087.001, T1021.001
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.16
Monitoring activities
8T1078, T1133, T1068, T1003
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.26
Application security requirements
8T1078, T1133, T1068, T1055
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.28
Secure coding
8T1133, T1547.001, T1068, T1070.004
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.8
Management of technical vulnerabilities
8T1078, T1068, T1055, T1027
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.2
Privileged access rights
8T1059, T1068, T1070, T1003
RESPOND
RESPOND (RS) — Take action regarding a detected…
A.8.28
Secure coding
8T1190, T1068, T1070.004, T1003.001
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
A.5.7
Threat intelligence
7T1087, T1003, T1190, T1036
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
A.8.16
Monitoring activities
7T1046, T1087, T1003, T1036
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
A.8.2
Privileged access rights
7T1087, T1018, T1003, T1053
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.26
Application security requirements
7T1190, T1059, T1068, T1003
RESPOND
RESPOND (RS) — Take action regarding a detected…
A.8.23
Web filtering
7T1068, T1003.001, T1021.001, T1005
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.5.7
Threat intelligence
6T1068, T1027, T1003, T1087
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.23
Web filtering
6T1547.001, T1068, T1027, T1021.001
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
A.8.2
Privileged access rights
6T1078, T1068, T1003, T1087
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
A.8.26
Application security requirements
6T1083, T1003, T1190, T1021
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.28
Secure coding
6T1190, T1059, T1068, T1027
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
A.8.9
Configuration management
6T1190, T1068, T1003, T1046
RESPOND
RESPOND (RS) — Take action regarding a detected…
A.8.21
Security of network services
6T1190, T1068, T1070.004, T1021.001

Showing top 25 of 83 control pairs.

Show non-overlap — NIST CSF techniques NOT covered by ISO 27001 (23)
T1004, T1009, T1011.001, T1014, T1015, T1035, T1036.003, T1037.001, T1038, T1048.003, T1053.005, T1056, T1059.003, T1195, T1491, T1498, T1529, T1531, T1561.001, T1561.002, T1565.001, T1566.001, T1595
Sourced from cs-graph compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.
Framework crosswalk — Jaccard similarity grid | SQUR Knowledge Base