Threat Mitigation Mapping

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

Instructions onlySecurity
AI-generated overview

Maps identified threats to security controls and mitigations for remediation and risk planning.

What it does
This skill guides the mapping of identified threats to appropriate security controls and mitigations. It explains control categories (preventive, detective, corrective), control layers such as network, application, data, endpoint and process, and defense-in-depth concepts. It points to a reference file containing templates for mitigation models, gap reporting, recommendations, implementation roadmaps and results by control.
When to use it
Use it when prioritizing security investments, building remediation roadmaps, validating control coverage, designing defense in depth, reviewing security architecture, or planning risk treatment.
Requirements
No scripts or tools are required; it is instructions only. It references a bundled reference file (references/details.md) for templates and worked examples.

Threat Mitigation Mapping

Connect threats to controls for effective security planning.

When to Use This Skill

  • Prioritizing security investments
  • Creating remediation roadmaps
  • Validating control coverage
  • Designing defense-in-depth
  • Security architecture review
  • Risk treatment planning

Core Concepts

1. Control Categories

Preventive ────► Stop attacks before they occur   │              (Firewall, Input validation)   │Detective ─────► Identify attacks in progress   │              (IDS, Log monitoring)   │Corrective ────► Respond and recover from attacks                  (Incident response, Backup restore)

2. Control Layers

LayerExamples
NetworkFirewall, WAF, DDoS protection
ApplicationInput validation, authentication
DataEncryption, access controls
EndpointEDR, patch management
ProcessSecurity training, incident response

3. Defense in Depth

                    ┌──────────────────────┐                    │      Perimeter       │ ← Firewall, WAF                    │   ┌──────────────┐   │                    │   │   Network    │   │ ← Segmentation, IDS                    │   │  ┌────────┐  │   │                    │   │  │  Host  │  │   │ ← EDR, Hardening                    │   │  │ ┌────┐ │  │   │                    │   │  │ │App │ │  │   │ ← Auth, Validation                    │   │  │ │Data│ │  │   │ ← Encryption                    │   │  │ └────┘ │  │   │                    │   │  └────────┘  │   │                    │   └──────────────┘   │                    └──────────────────────┘

Templates and detailed worked examples

Full template library and detailed mitigation/control mappings live in references/details.md. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.

Best Practices

Do's

  • Map all threats - No threat should be unmapped
  • Layer controls - Defense in depth is essential
  • Mix control types - Preventive, detective, corrective
  • Track effectiveness - Measure and improve
  • Review regularly - Controls degrade over time

Don'ts

  • Don't rely on single controls - Single points of failure
  • Don't ignore cost - ROI matters
  • Don't skip testing - Untested controls may fail
  • Don't set and forget - Continuous improvement
  • Don't ignore people/process - Technology alone isn't enough

Source and attribution

Source:wshobson/agentsinplugins/security-scanning/skills/threat-mitigation-mappingat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal