Cyber Resilience

Controls

What actually mitigates, mapped and graded — 30,810 cross-framework control mappings, 124 of 375 rolled-up controls and weaknesses verified as mostly-or-fully covered.

Last updated: 23 August 2026 00:24 UTC

Your region's control baseline: outside the US, ISO/IEC 27001:2022 Annex A is usually the primary control framework. See the ISO 27001 controls — each cross-walked to NIST 800-53, CSF, ASVS, CWE, ATT&CK and OWASP. Switch region in the header to show ISO controls on every CVE page.
Thinnest coverage — control families that miss the mostcurrent snapshot · 226 actors
  • CPContingency Planning — covers 20% of mapped technique surface on average across 3 actors5 controls
  • SASystem & Services Acquisition — covers 21% of mapped technique surface on average across 8 actors8 controls
  • RARisk Assessment — covers 25% of mapped technique surface on average across 189 actors3 controls
  • IAIdentification & Authentication — covers 27% of mapped technique surface on average across 201 actors10 controls
  • SCSystem & Comms Protection — covers 31% of mapped technique surface on average across 207 actors24 controls
  • ACAccess Control — covers 33% of mapped technique surface on average across 226 actors13 controls

Control gaps by actor

For each of the most active actors, the NIST 800-53 controls that mitigate the largest share of their ATT&CK techniques — and how much of their playbook even the best single control leaves uncovered.

ActorStart-here controls Best coverageUncovered share
Kimsuky171 techniquesSI-4CM-6CM-250%50%
APT28129 techniquesCM-6SI-4CM-261%39%
Lazarus Group128 techniquesSI-4CM-2CM-660%40%
APT41115 techniquesSI-4CM-6CM-264%36%
Mustang Panda114 techniquesSI-4CM-2CM-661%39%
Magic Hound109 techniquesSI-4CM-6CM-258%42%
Sandworm Team109 techniquesSI-4CM-6CM-259%41%
APT32106 techniquesSI-4CM-6CM-267%33%

Coverage = the share of an actor's ATT&CK techniques that our cross-walks map the control as mitigating. How actor data is built.