Threat Mitigation Mapping

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

僅含說明Security
AI 產生的概覽

將已識別的威脅對應到安全控制與緩解措施,用於修復與風險規劃。

功能
此技能指引如何將已識別的威脅對應到合適的安全控制與緩解措施。它說明控制類別(預防性、偵測性、矯正性)、網路、應用程式、資料、端點與流程等控制層次,以及縱深防禦概念。它指向一份參考檔案,內含緩解模型、缺口報告、建議、導入藍圖與依控制分類的結果等範本。
適用情境
適用於排定安全投資優先順序、擬定修復藍圖、驗證控制涵蓋範圍、設計縱深防禦、審查安全架構或規劃風險處理時。
執行需求
不需要指令碼或工具,僅為說明性內容。它引用隨附的參考檔案(references/details.md)以取得範本與範例。

Threat Mitigation Mapping

Connect threats to controls for effective security planning.

When to Use This Skill

  • Prioritizing security investments
  • Creating remediation roadmaps
  • Validating control coverage
  • Designing defense-in-depth
  • Security architecture review
  • Risk treatment planning

Core Concepts

1. Control Categories

Preventive ────► Stop attacks before they occur   │              (Firewall, Input validation)   │Detective ─────► Identify attacks in progress   │              (IDS, Log monitoring)   │Corrective ────► Respond and recover from attacks                  (Incident response, Backup restore)

2. Control Layers

LayerExamples
NetworkFirewall, WAF, DDoS protection
ApplicationInput validation, authentication
DataEncryption, access controls
EndpointEDR, patch management
ProcessSecurity training, incident response

3. Defense in Depth

                    ┌──────────────────────┐                    │      Perimeter       │ ← Firewall, WAF                    │   ┌──────────────┐   │                    │   │   Network    │   │ ← Segmentation, IDS                    │   │  ┌────────┐  │   │                    │   │  │  Host  │  │   │ ← EDR, Hardening                    │   │  │ ┌────┐ │  │   │                    │   │  │ │App │ │  │   │ ← Auth, Validation                    │   │  │ │Data│ │  │   │ ← Encryption                    │   │  │ └────┘ │  │   │                    │   │  └────────┘  │   │                    │   └──────────────┘   │                    └──────────────────────┘

Templates and detailed worked examples

Full template library and detailed mitigation/control mappings live in references/details.md. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.

Best Practices

Do's

  • Map all threats - No threat should be unmapped
  • Layer controls - Defense in depth is essential
  • Mix control types - Preventive, detective, corrective
  • Track effectiveness - Measure and improve
  • Review regularly - Controls degrade over time

Don'ts

  • Don't rely on single controls - Single points of failure
  • Don't ignore cost - ROI matters
  • Don't skip testing - Untested controls may fail
  • Don't set and forget - Continuous improvement
  • Don't ignore people/process - Technology alone isn't enough

來源與署名

來源:wshobson/agents位於plugins/security-scanning/skills/threat-mitigation-mapping提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架