14 frameworks127 controls

CROSSWALKFramework crosswalk

14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.

Cells coloured by Jaccard similarity of technique sets.

01
DORAISO 27001PCI DSS v4CIS v8NIS2OWASP API Top 10OWASP LLM Top 10OWASP Top 10ISO 27701EU AI ActGDPRNIST CSFEU CRATIBER-EU
DORA
0.400.360.480.540.230.310.330.290.260.450.460.19
ISO 270010.40
0.330.530.440.300.290.340.280.250.400.360.14
PCI DSS v40.360.33
0.410.410.330.350.330.390.400.300.330.29
CIS v80.480.530.41
0.540.330.330.390.290.300.510.480.19
NIS20.540.440.410.54
0.330.360.320.320.270.450.470.22
OWASP API Top 100.230.300.330.330.33
0.360.350.260.200.250.310.11
OWASP LLM Top 100.310.290.350.330.360.36
0.390.390.310.370.390.21
OWASP Top 100.330.340.330.390.320.350.39
0.280.270.310.350.17
ISO 277010.290.280.390.290.320.260.390.28
0.300.380.260.29
EU AI Act0.260.250.400.300.270.200.310.270.30
0.400.310.27
GDPR0.450.400.300.510.450.250.370.310.380.40
0.440.21
NIST CSF0.460.360.330.480.470.310.390.350.260.310.44
0.18
EU CRA
TIBER-EU0.190.140.290.190.220.110.210.170.290.270.210.18

OWASP API Top 10NIST CSF 27 shared techniques

Clear ✕
Control AControl BSharedExamples
API8:2023
Security Misconfiguration
RESPOND
RESPOND (RS) — Take action regarding a detected…
9T1190, T1059.003, T1068, T1070.004
API8:2023
Security Misconfiguration
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
8T1133, T1068, T1055, T1070.004
API6:2023
Unrestricted Access to Sensitive Business Flows
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
7T1190, T1059, T1068, T1046
API1:2023
Broken Object Level Authorization (BOLA)
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
5T1005, T1041, T1133, T1078
API6:2023
Unrestricted Access to Sensitive Business Flows
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
5T1078, T1068, T1046, T1087
API1:2023
Broken Object Level Authorization (BOLA)
RECOVER
RECOVER (RC) — Restore assets and operations af…
4T1005, T1041, T1485, T1490
API3:2023
Broken Object Property Level Authorization (BOPLA)
RECOVER
RECOVER (RC) — Restore assets and operations af…
4T1485, T1490, T1565.001, T1098
API6:2023
Unrestricted Access to Sensitive Business Flows
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
4T1190, T1046, T1087, T1005
API7:2023
Server-Side Request Forgery (SSRF)
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
4T1046, T1552.001, T1005, T1041
API7:2023
Server-Side Request Forgery (SSRF)
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
4T1190, T1046, T1018, T1005
API7:2023
Server-Side Request Forgery (SSRF)
RECOVER
RECOVER (RC) — Restore assets and operations af…
4T1005, T1071.001, T1041, T1490
API7:2023
Server-Side Request Forgery (SSRF)
RESPOND
RESPOND (RS) — Take action regarding a detected…
4T1190, T1005, T1071.001, T1041
API1:2023
Broken Object Level Authorization (BOLA)
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
3T1595, T1005, T1083
API1:2023
Broken Object Level Authorization (BOLA)
RESPOND
RESPOND (RS) — Take action regarding a detected…
3T1005, T1041, T1068
API3:2023
Broken Object Property Level Authorization (BOPLA)
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
3T1078, T1087, T1003
API3:2023
Broken Object Property Level Authorization (BOPLA)
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
3T1087, T1003, T1083
API3:2023
Broken Object Property Level Authorization (BOPLA)
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
3T1087, T1003, T1059
API6:2023
Unrestricted Access to Sensitive Business Flows
RESPOND
RESPOND (RS) — Take action regarding a detected…
3T1190, T1068, T1005
API7:2023
Server-Side Request Forgery (SSRF)
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
3T1190, T1046, T1005
API8:2023
Security Misconfiguration
DETECT
DETECT (DE) — Find and analyse possible cyberse…
3T1003.001, T1046, T1021.001
API8:2023
Security Misconfiguration
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
3T1190, T1068, T1046
API1:2023
Broken Object Level Authorization (BOLA)
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
2T1005, T1068
API2:2023
Broken Authentication
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
2T1078, T1068
API2:2023
Broken Authentication
RESPOND
RESPOND (RS) — Take action regarding a detected…
2T1098, T1068
API6:2023
Unrestricted Access to Sensitive Business Flows
DETECT
DETECT (DE) — Find and analyse possible cyberse…
2T1046, T1005

Showing top 25 of 33 control pairs.

Show non-overlap — OWASP API Top 10 techniques NOT covered by NIST CSF (30)
T1003.008, T1020, T1074, T1074.001, T1078.004, T1082, T1087.004, T1090.003, T1098.005, T1110, T1110.003, T1110.004, T1119, T1136, T1498.001, T1499, T1530, T1537, T1539, T1550.001, T1550.004, T1552, T1552.007, T1552.008, T1556.006, T1562, T1567, T1572, T1592, T1595.002
Sourced from cs-graph compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.
Framework crosswalk — Jaccard similarity grid | SQUR Knowledge Base