Threat Mitigation Mapping

作者 wshobson46891e7e60da无许可证40K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

仅含说明Security
AI 生成的概览

将已识别的威胁映射到安全控制与缓解措施,用于修复和风险规划。

功能
该技能指导如何将已识别的威胁映射到相应的安全控制与缓解措施。它讲解控制类别(预防性、检测性、纠正性)、网络、应用、数据、终端和流程等控制层次,以及纵深防御概念。它指向一个参考文件,其中包含缓解模型、差距报告、建议、实施路线图和按控制分类的结果等模板。
适用场景
适用于确定安全投资优先级、制定修复路线图、验证控制覆盖范围、设计纵深防御、评审安全架构或规划风险处置时。
运行要求
无需脚本或工具,仅为说明性内容。它引用随附的参考文件(references/details.md)以获取模板和示例。

Threat Mitigation Mapping

Connect threats to controls for effective security planning.

When to Use This Skill

  • Prioritizing security investments
  • Creating remediation roadmaps
  • Validating control coverage
  • Designing defense-in-depth
  • Security architecture review
  • Risk treatment planning

Core Concepts

1. Control Categories

Preventive ────► Stop attacks before they occur   │              (Firewall, Input validation)   │Detective ─────► Identify attacks in progress   │              (IDS, Log monitoring)   │Corrective ────► Respond and recover from attacks                  (Incident response, Backup restore)

2. Control Layers

LayerExamples
NetworkFirewall, WAF, DDoS protection
ApplicationInput validation, authentication
DataEncryption, access controls
EndpointEDR, patch management
ProcessSecurity training, incident response

3. Defense in Depth

                    ┌──────────────────────┐                    │      Perimeter       │ ← Firewall, WAF                    │   ┌──────────────┐   │                    │   │   Network    │   │ ← Segmentation, IDS                    │   │  ┌────────┐  │   │                    │   │  │  Host  │  │   │ ← EDR, Hardening                    │   │  │ ┌────┐ │  │   │                    │   │  │ │App │ │  │   │ ← Auth, Validation                    │   │  │ │Data│ │  │   │ ← Encryption                    │   │  │ └────┘ │  │   │                    │   │  └────────┘  │   │                    │   └──────────────┘   │                    └──────────────────────┘

Templates and detailed worked examples

Full template library and detailed mitigation/control mappings live in references/details.md. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.

Best Practices

Do's

  • Map all threats - No threat should be unmapped
  • Layer controls - Defense in depth is essential
  • Mix control types - Preventive, detective, corrective
  • Track effectiveness - Measure and improve
  • Review regularly - Controls degrade over time

Don'ts

  • Don't rely on single controls - Single points of failure
  • Don't ignore cost - ROI matters
  • Don't skip testing - Untested controls may fail
  • Don't set and forget - Continuous improvement
  • Don't ignore people/process - Technology alone isn't enough

来源与署名

来源:wshobson/agents位于plugins/security-scanning/skills/threat-mitigation-mapping提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架