14 frameworks127 controls

CROSSWALKFramework crosswalk

14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.

Cells coloured by Jaccard similarity of technique sets.

01
DORAISO 27001PCI DSS v4CIS v8NIS2OWASP API Top 10OWASP LLM Top 10OWASP Top 10ISO 27701EU AI ActGDPRNIST CSFEU CRATIBER-EU
DORA
0.400.360.480.540.230.310.330.290.260.450.460.19
ISO 270010.40
0.330.530.440.300.290.340.280.250.400.360.14
PCI DSS v40.360.33
0.410.410.330.350.330.390.400.300.330.29
CIS v80.480.530.41
0.540.330.330.390.290.300.510.480.19
NIS20.540.440.410.54
0.330.360.320.320.270.450.470.22
OWASP API Top 100.230.300.330.330.33
0.360.350.260.200.250.310.11
OWASP LLM Top 100.310.290.350.330.360.36
0.390.390.310.370.390.21
OWASP Top 100.330.340.330.390.320.350.39
0.280.270.310.350.17
ISO 277010.290.280.390.290.320.260.390.28
0.300.380.260.29
EU AI Act0.260.250.400.300.270.200.310.270.30
0.400.310.27
GDPR0.450.400.300.510.450.250.370.310.380.40
0.440.21
NIST CSF0.460.360.330.480.470.310.390.350.260.310.44
0.18
EU CRA
TIBER-EU0.190.140.290.190.220.110.210.170.290.270.210.18

NIST CSFOWASP LLM Top 10 31 shared techniques

Clear ✕
Control AControl BSharedExamples
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
LLM05:2025
Improper Output Handling
9T1190, T1059, T1068, T1027
RESPOND
RESPOND (RS) — Take action regarding a detected…
LLM06:2025
Excessive Agency
7T1068, T1070.004, T1005, T1071.001
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
LLM04:2025
Data and Model Poisoning
6T1083, T1003, T1195, T1036
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
LLM04:2025
Data and Model Poisoning
6T1547, T1068, T1003, T1021
RECOVER
RECOVER (RC) — Restore assets and operations af…
LLM03:2025
Supply Chain
6T1485, T1490, T1562.001, T1005
RESPOND
RESPOND (RS) — Take action regarding a detected…
LLM03:2025
Supply Chain
6T1068, T1021.001, T1005, T1041
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM03:2025
Supply Chain
5T1547.001, T1068, T1021.001, T1005
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM04:2025
Data and Model Poisoning
5T1078, T1068, T1003, T1005
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM06:2025
Excessive Agency
5T1133, T1547.001, T1068, T1070.004
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
LLM02:2025
Sensitive Information Disclosure
5T1595, T1087, T1083, T1018
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
LLM05:2025
Improper Output Handling
5T1083, T1003, T1190, T1021
RECOVER
RECOVER (RC) — Restore assets and operations af…
LLM06:2025
Excessive Agency
5T1485, T1490, T1005, T1071.001
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM02:2025
Sensitive Information Disclosure
4T1027, T1087, T1005, T1041
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM05:2025
Improper Output Handling
4T1068, T1027, T1003, T1041
GOVERN
GOVERN (GV) — Establish and monitor the cyberse…
LLM07:2025
System Prompt Leakage
4T1027, T1003, T1005, T1041
IDENTIFY
IDENTIFY (ID) — Understand organisational cyber…
LLM07:2025
System Prompt Leakage
4T1083, T1003, T1190, T1005
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
LLM07:2025
System Prompt Leakage
4T1190, T1027, T1003, T1005
RESPOND
RESPOND (RS) — Take action regarding a detected…
LLM05:2025
Improper Output Handling
4T1190, T1068, T1041, T1486
RESPOND
RESPOND (RS) — Take action regarding a detected…
LLM07:2025
System Prompt Leakage
4T1190, T1005, T1041, T1566.001
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
LLM02:2025
Sensitive Information Disclosure
3T1027, T1087, T1005
PROTECT
PROTECT (PR) — Use safeguards to manage cyberse…
LLM06:2025
Excessive Agency
3T1068, T1005, T1486
RECOVER
RECOVER (RC) — Restore assets and operations af…
LLM04:2025
Data and Model Poisoning
3T1490, T1005, T1041
RECOVER
RECOVER (RC) — Restore assets and operations af…
LLM07:2025
System Prompt Leakage
3T1490, T1005, T1041
RESPOND
RESPOND (RS) — Take action regarding a detected…
LLM04:2025
Data and Model Poisoning
3T1068, T1005, T1041
DETECT
DETECT (DE) — Find and analyse possible cyberse…
LLM03:2025
Supply Chain
2T1021.001, T1005

Showing top 25 of 35 control pairs.

Show non-overlap — NIST CSF techniques NOT covered by OWASP LLM Top 10 (27)
T1003.001, T1004, T1009, T1011.001, T1014, T1015, T1033, T1035, T1036.003, T1037.001, T1038, T1046, T1048.003, T1049, T1053, T1053.005, T1055, T1070, T1087.001, T1098, T1491, T1498, T1529, T1552.001, T1561.001, T1561.002, T1566
Sourced from cs-graph compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.
Framework crosswalk — Jaccard similarity grid | SQUR Knowledge Base