Controls
What actually mitigates, mapped and graded — 30,810 cross-framework control mappings, 124 of 375 rolled-up controls and weaknesses verified as mostly-or-fully covered.
Last updated: 23 August 2026 00:24 UTC
Your region's control baseline: outside the US, ISO/IEC
27001:2022 Annex A is usually the primary control framework. See the
ISO 27001 controls — each cross-walked to
NIST 800-53, CSF, ASVS, CWE, ATT&CK and OWASP. Switch region in
the header to show ISO controls on every CVE page.
Act
Control gaps by actorthe busiest actors' techniques vs the controls that mitigate them — and what even the best control missesControls coverageNIST 800-53 controls mapped to the techniques and CVEs they mitigateHardening rulesDISA STIG host-hardening rules, cross-walked to 800-53Explore
Framework cross-walks30,810 graded mappings between security frameworksCross-walk explorerbrowse every mapping; filter by framework, verb, and grade800-53 cumulative coveragehow much of NIST 800-53 the mapped frameworks reachCWE cumulative coveragewhich weakness classes the control frameworks preventNIST CSF 2.0functions, categories, and their 800-53 mappingsOWASP ASVS 5.0application security verification requirementsOWASP Top 10 Web 2025category pages with per-CVE taggingCWE weakness catalogue748 weakness classes with blind spots flaggedUnderstand
Does my defence line up?which control families carry the mitigation weight, by frameworkHow cross-walks workthe taxonomy: verbs, directions, and extent gradesThe cross-walk illusionwhy chained mappings lose most of the signalGrading the machinehow reliable are LLM-authored security cross-walks?Risk scoring explainedhow the 0–100 composite score worksThinnest coverage — control families that miss the mostcurrent snapshot · 226 actors
- CPContingency Planning — covers 20% of mapped technique surface on average across 3 actors5 controls
- SASystem & Services Acquisition — covers 21% of mapped technique surface on average across 8 actors8 controls
- RARisk Assessment — covers 25% of mapped technique surface on average across 189 actors3 controls
- IAIdentification & Authentication — covers 27% of mapped technique surface on average across 201 actors10 controls
- SCSystem & Comms Protection — covers 31% of mapped technique surface on average across 207 actors24 controls
- ACAccess Control — covers 33% of mapped technique surface on average across 226 actors13 controls
Control gaps by actor
For each of the most active actors, the NIST 800-53 controls that mitigate the largest share of their ATT&CK techniques — and how much of their playbook even the best single control leaves uncovered.
| Actor | Start-here controls | Best coverage | Uncovered share |
|---|---|---|---|
| Kimsuky171 techniques | SI-4CM-6CM-2 | 50% | 50% |
| APT28129 techniques | CM-6SI-4CM-2 | 61% | 39% |
| Lazarus Group128 techniques | SI-4CM-2CM-6 | 60% | 40% |
| APT41115 techniques | SI-4CM-6CM-2 | 64% | 36% |
| Mustang Panda114 techniques | SI-4CM-2CM-6 | 61% | 39% |
| Magic Hound109 techniques | SI-4CM-6CM-2 | 58% | 42% |
| Sandworm Team109 techniques | SI-4CM-6CM-2 | 59% | 41% |
| APT32106 techniques | SI-4CM-6CM-2 | 67% | 33% |
Coverage = the share of an actor's ATT&CK techniques that our cross-walks map the control as mitigating. How actor data is built.