14 frameworks127 controls

CROSSWALKFramework crosswalk

14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.

Cells coloured by Jaccard similarity of technique sets.

01
DORAISO 27001PCI DSS v4CIS v8NIS2OWASP API Top 10OWASP LLM Top 10OWASP Top 10ISO 27701EU AI ActGDPRNIST CSFEU CRATIBER-EU
DORA
0.400.360.480.540.230.310.330.290.260.450.460.19
ISO 270010.40
0.330.530.440.300.290.340.280.250.400.360.14
PCI DSS v40.360.33
0.410.410.330.350.330.390.400.300.330.29
CIS v80.480.530.41
0.540.330.330.390.290.300.510.480.19
NIS20.540.440.410.54
0.330.360.320.320.270.450.470.22
OWASP API Top 100.230.300.330.330.33
0.360.350.260.200.250.310.11
OWASP LLM Top 100.310.290.350.330.360.36
0.390.390.310.370.390.21
OWASP Top 100.330.340.330.390.320.350.39
0.280.270.310.350.17
ISO 277010.290.280.390.290.320.260.390.28
0.300.380.260.29
EU AI Act0.260.250.400.300.270.200.310.270.30
0.400.310.27
GDPR0.450.400.300.510.450.250.370.310.380.40
0.440.21
NIST CSF0.460.360.330.480.470.310.390.350.260.310.44
0.18
EU CRA
TIBER-EU0.190.140.290.190.220.110.210.170.290.270.210.18

CIS v8NIS2 41 shared techniques

Clear ✕
Control AControl BSharedExamples
CIS Control 18
Penetration Testing
Art. 21(2)(a)
Policies on risk analysis and information syste…
12T1068, T1547, T1027, T1003
CIS Control 16
Application Software Security
Art. 21(2)(a)
Policies on risk analysis and information syste…
11T1133, T1068, T1027, T1036
CIS Control 2
Inventory and Control of Software Assets
Art. 21(2)(b)
Incident handling
11T1078, T1021, T1059, T1047
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(a)
Policies on risk analysis and information syste…
10T1078, T1133, T1068, T1027
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(b)
Incident handling
10T1078, T1059, T1133, T1027
CIS Control 18
Penetration Testing
Art. 21(2)(b)
Incident handling
10T1059, T1027, T1003, T1046
CIS Control 18
Penetration Testing
Art. 21(2)(d)
Supply chain security
10T1068, T1547, T1027, T1003
CIS Control 18
Penetration Testing
Art. 21(2)(f)
Policies and procedures to assess the effective…
10T1190, T1566, T1068, T1027
CIS Control 4
Secure Configuration of Enterprise Assets and S…
Art. 21(2)(f)
Policies and procedures to assess the effective…
10T1190, T1547.001, T1068, T1027
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(d)
Supply chain security
9T1068, T1027, T1018, T1021
CIS Control 16
Application Software Security
Art. 21(2)(b)
Incident handling
9T1133, T1027, T1036, T1003
CIS Control 16
Application Software Security
Art. 21(2)(d)
Supply chain security
9T1068, T1027, T1003, T1021
CIS Control 18
Penetration Testing
Art. 21(2)(g)
Basic cyber hygiene practices and cybersecurity…
9T1566, T1059, T1027, T1003
CIS Control 1
Inventory and Control of Enterprise Assets
Art. 21(2)(a)
Policies on risk analysis and information syste…
9T1046, T1133, T1547, T1068
CIS Control 5
Account Management
Art. 21(2)(a)
Policies on risk analysis and information syste…
9T1078, T1133, T1003, T1087
CIS Control 5
Account Management
Art. 21(2)(b)
Incident handling
9T1078, T1133, T1003, T1087
CIS Control 5
Account Management
Art. 21(2)(g)
Basic cyber hygiene practices and cybersecurity…
9T1078, T1133, T1098, T1003
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(e)
Security in network and information systems acq…
8T1190, T1078, T1059, T1068
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(f)
Policies and procedures to assess the effective…
8T1190, T1078, T1068, T1027
CIS Control 13
Network Monitoring and Defense
Art. 21(2)(g)
Basic cyber hygiene practices and cybersecurity…
8T1078, T1059, T1133, T1027
CIS Control 16
Application Software Security
Art. 21(2)(f)
Policies and procedures to assess the effective…
8T1190, T1547.001, T1068, T1027
CIS Control 18
Penetration Testing
Art. 21(2)(e)
Security in network and information systems acq…
8T1190, T1059, T1068, T1003
CIS Control 1
Inventory and Control of Enterprise Assets
Art. 21(2)(d)
Supply chain security
8T1018, T1547, T1068, T1071
CIS Control 2
Inventory and Control of Software Assets
Art. 21(2)(a)
Policies on risk analysis and information syste…
8T1078, T1021, T1027, T1036
CIS Control 2
Inventory and Control of Software Assets
Art. 21(2)(i)
Human resources security, access control polici…
8T1021, T1037, T1015, T1027

Showing top 25 of 110 control pairs.

Show non-overlap — CIS v8 techniques NOT covered by NIS2 (19)
T1003.003, T1003.005, T1036.005, T1042, T1059.003, T1070, T1070.001, T1078.001, T1078.002, T1087.001, T1090, T1136, T1210, T1530, T1543.003, T1548.002, T1552.001, T1562, T1566.001
Sourced from cs-graph compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.
Framework crosswalk — Jaccard similarity grid | SQUR Knowledge Base