CROSSWALKS

GAISSF to MITRE ATTACK Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to MITRE ATTACK, with scope, method, limitations and traceability.

1. Executive Summary

CRO-026 documents defensive relationships between all 59 GAISSF v1.0 controls and a source-bounded priority set of 100 MITRE ATT&CK Enterprise techniques across all 14 Enterprise tactics. The register contains 112 control-to-technique mapping records and a reverse tactic-level coverage view.

The crosswalk supports threat modelling, detection and telemetry planning, adversary-emulation scoping, evidence reuse, and assurance design. It does not convert ATT&CK into a compliance checklist and does not prove that any mapped technique is prevented, detected, or mitigated in operation.

2. Purpose and Intended Use

  • Translate adversary behavior into GAISSF control and evidence requirements.

  • Support SOC, threat-intelligence, red-team, purple-team, architecture, and assurance collaboration.

  • Identify control, telemetry, detection, resilience, and testing gaps.

  • Provide a repeatable source for GitHub, automation, and assessment tooling.

3. Scope

Primary scope: MITRE ATT&CK Enterprise v19. Mobile and ICS are excluded from this edition because their techniques, platforms, operational consequences, and evidence expectations require separate controlled profiles. The official ATT&CK dataset remains authoritative for the complete current technique, sub-technique, procedure, mitigation, detection-strategy, group, software, and campaign inventory.

4. Source Baseline

Source Version / status Use in CRO-026
GAISSF Framework Standard GAISSF-NOR-001 v1.0, normative Architecture, conformance language and source authority
GAISSF Control Catalogue GAISSF-NOR-004 v1.0, normative Authoritative 59-control baseline
MITRE ATT&CK Version 19, released 28 April 2026 Enterprise tactics and technique identifiers
ATT&CK STIX Data Official MITRE GitHub repository Machine-readable source and future revalidation

5. Mapping Methodology

  • Map substantive defensive outcomes, not labels.

  • Use technique-level records; sub-technique and procedure analysis remains contextual.

  • Separate relationship strength from confidence.

  • Treat multiple GAISSF controls supporting one ATT&CK behavior as composite coverage.

  • Record residual gaps for telemetry, procedure analysis, threat relevance, emulation, and operating effectiveness.

  • Perform reverse tactic coverage to identify silent omissions.

6. Controlled Vocabulary

Code Meaning
E Equivalent or near-equivalent; exceptional threshold
SP Strong partial
P Partial
S Supporting
C Contextual
N No material mapping
O Outside scope
U Unable to determine

7. Enterprise Tactic Coverage

Tactic ID Tactic Mapped controls Coverage Confidence
TA0043 Reconnaissance 10 Substantially Addressed Medium-High
TA0042 Resource Development 8 Substantially Addressed Medium-High
TA0001 Initial Access 32 Substantially Addressed Medium-High
TA0002 Execution 5 Partially Addressed Medium
TA0003 Persistence 10 Substantially Addressed Medium-High
TA0004 Privilege Escalation 1 Partially Addressed Medium
TA0005 Defense Evasion 9 Substantially Addressed Medium-High
TA0006 Credential Access 1 Partially Addressed Medium
TA0007 Discovery 2 Partially Addressed Medium
TA0008 Lateral Movement 2 Partially Addressed Medium
TA0009 Collection 1 Partially Addressed Medium
TA0011 Command and Control 0 Not Addressed Not Rated
TA0010 Exfiltration 6 Partially Addressed Medium
TA0040 Impact 12 Substantially Addressed Medium-High

8. Function-by-Function Analysis

TA0043 - Reconnaissance

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-04, D3-CTL-05, D7-CTL-H01, D7-CTL-H02, D7-CTL-H04, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0042 - Resource Development

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-07, D6-CTL-06, D8-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0001 - Initial Access

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-01, D2-CTL-03, D2-CTL-05, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-06, D3-CTL-07, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-03, D6-CTL-05, D6-CTL-06, D7-CTL-H01, D7-CTL-H05, D9-CTL-03, D9-CTL-04, D9-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0002 - Execution

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-04, D7-CTL-H02. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0003 - Persistence

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D6-CTL-01, D6-CTL-04. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0004 - Privilege Escalation

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D7-CTL-H03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0005 - Defense Evasion

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-01, D2-CTL-06, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-07, D6-CTL-02, D9-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0006 - Credential Access

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D7-CTL-H03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0007 - Discovery

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D4-CTL-06, D6-CTL-02. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0008 - Lateral Movement

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D3-CTL-01, D3-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0009 - Collection

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D2-CTL-03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0011 - Command and Control

Coverage assessment: Not Addressed (Not Rated confidence). Mapped GAISSF controls: None. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0010 - Exfiltration

Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

TA0040 - Impact

Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-02, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06, D6-CTL-07, D8-CTL-04, D9-CTL-01, D9-CTL-02, D9-CTL-07. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.

9. Priority Technique Inventory

Technique ID Technique Tactic
T1595 Active Scanning Reconnaissance
T1592 Gather Victim Host Information Reconnaissance
T1589 Gather Victim Identity Information Reconnaissance
T1590 Gather Victim Network Information Reconnaissance
T1591 Gather Victim Org Information Reconnaissance
T1593 Search Open Websites/Domains Reconnaissance
T1594 Search Victim-Owned Websites Reconnaissance
T1596 Search Open Technical Databases Reconnaissance
T1583 Acquire Infrastructure Resource Development
T1584 Compromise Infrastructure Resource Development
T1585 Establish Accounts Resource Development
T1586 Compromise Accounts Resource Development
T1587 Develop Capabilities Resource Development
T1588 Obtain Capabilities Resource Development
T1608 Stage Capabilities Resource Development
T1189 Drive-by Compromise Initial Access
T1190 Exploit Public-Facing Application Initial Access
T1133 External Remote Services Initial Access
T1566 Phishing Initial Access
T1195 Supply Chain Compromise Initial Access
T1078 Valid Accounts Initial Access
T1059 Command and Scripting Interpreter Execution
T1203 Exploitation for Client Execution Execution
T1204 User Execution Execution
T1047 Windows Management Instrumentation Execution
T1129 Shared Modules Execution
T1106 Native API Execution
T1053 Scheduled Task/Job Execution
T1127 Trusted Developer Utilities Proxy Execution Execution
T1098 Account Manipulation Persistence
T1547 Boot or Logon Autostart Execution Persistence
T1136 Create Account Persistence
T1505 Server Software Component Persistence
T1525 Implant Internal Image Persistence
T1554 Compromise Host Software Binary Persistence
T1053.003 Scheduled Task/Job: Cron Persistence
T1068 Exploitation for Privilege Escalation Privilege Escalation
T1548 Abuse Elevation Control Mechanism Privilege Escalation
T1134 Access Token Manipulation Privilege Escalation
T1484 Domain or Tenant Policy Modification Privilege Escalation
T1027 Obfuscated Files or Information Defense Evasion
T1070 Indicator Removal Defense Evasion
T1036 Masquerading Defense Evasion
T1562 Impair Defenses Defense Evasion
T1553 Subvert Trust Controls Defense Evasion
T1218 System Binary Proxy Execution Defense Evasion
T1222 File and Directory Permissions Modification Defense Evasion
T1497 Virtualization/Sandbox Evasion Defense Evasion
T1574 Hijack Execution Flow Defense Evasion
T1110 Brute Force Credential Access
T1555 Credentials from Password Stores Credential Access
T1552 Unsecured Credentials Credential Access
T1003 OS Credential Dumping Credential Access
T1528 Steal Application Access Token Credential Access
T1539 Steal Web Session Cookie Credential Access
T1649 Steal or Forge Authentication Certificates Credential Access
T1621 Multi-Factor Authentication Request Generation Credential Access
T1087 Account Discovery Discovery
T1580 Cloud Infrastructure Discovery Discovery
T1613 Container and Resource Discovery Discovery
T1526 Cloud Service Discovery Discovery
T1083 File and Directory Discovery Discovery
T1049 System Network Connections Discovery Discovery
T1018 Remote System Discovery Discovery
T1518 Software Discovery Discovery
T1482 Domain Trust Discovery Discovery
T1614 System Location Discovery Discovery
T1021 Remote Services Lateral Movement
T1570 Lateral Tool Transfer Lateral Movement
T1210 Exploitation of Remote Services Lateral Movement
T1550 Use Alternate Authentication Material Lateral Movement
T1119 Automated Collection Collection
T1213 Data from Information Repositories Collection
T1530 Data from Cloud Storage Collection
T1114 Email Collection Collection
T1005 Data from Local System Collection
T1074 Data Staged Collection
T1560 Archive Collected Data Collection
T1056 Input Capture Collection
T1071 Application Layer Protocol Command and Control
T1105 Ingress Tool Transfer Command and Control
T1090 Proxy Command and Control
T1219 Remote Access Software Command and Control
T1572 Protocol Tunneling Command and Control
T1102 Web Service Command and Control
T1048 Exfiltration Over Alternative Protocol Exfiltration
T1567 Exfiltration Over Web Service Exfiltration
T1537 Transfer Data to Cloud Account Exfiltration
T1020 Automated Exfiltration Exfiltration
T1041 Exfiltration Over C2 Channel Exfiltration
T1052 Exfiltration Over Physical Medium Exfiltration
T1486 Data Encrypted for Impact Impact
T1485 Data Destruction Impact
T1490 Inhibit System Recovery Impact
T1498 Network Denial of Service Impact
T1499 Endpoint Denial of Service Impact
T1565 Data Manipulation Impact
T1531 Account Access Removal Impact
T1529 System Shutdown/Reboot Impact
T1657 Financial Theft Impact

10. Detailed Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 112 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF control ATT&CK technique Tactic Rel. Conf.
CRO026-MAP-0001 D1-CTL-01 Dataset Provenance & Poisoning Prevention T1195 Supply Chain Compromise Initial Access S Low
CRO026-MAP-0002 D1-CTL-01 Dataset Provenance & Poisoning Prevention T1554 Compromise Host Software Binary Persistence S Low
CRO026-MAP-0003 D1-CTL-02 Model Extraction Resistance T1195 Supply Chain Compromise Initial Access S Low
CRO026-MAP-0004 D1-CTL-02 Model Extraction Resistance T1554 Compromise Host Software Binary Persistence S Low
CRO026-MAP-0005 D1-CTL-03 Behavioral Drift Detection T1195 Supply Chain Compromise Initial Access S Low
CRO026-MAP-0006 D1-CTL-03 Behavioral Drift Detection T1554 Compromise Host Software Binary Persistence S Low

11. Evidence Reuse Guidance

  • Threat models, attack-path models, architecture diagrams and trust-boundary records.

  • Identity, access, secrets, privileged-access and service-account evidence.

  • Secure development, dependency, build, image and supplier assurance records.

  • Logging, telemetry, detection, alert triage and incident-response evidence.

  • Backup, restoration, resilience, denial-of-service and recovery test records.

  • Red-team, purple-team, penetration-test and adversary-emulation evidence.

12. Limitations

  • ATT&CK describes adversary behavior and is not a prescriptive control or compliance framework.

  • A mapping does not prove prevention, detection, mitigation effectiveness, or test coverage.

  • The priority technique inventory is scoped to Enterprise techniques with direct relevance to GAISSF and does not replace the complete official ATT&CK dataset.

  • Sub-techniques and procedures require environment-specific analysis.

  • Mobile and ICS domains are excluded from this edition and require separate controlled profiles.

  • ATT&CK changes require source revalidation.

13. Notably Absent

  • No MITRE endorsement, approval, certification, or recognition.

  • No claim of complete prevention or detection of an ATT&CK technique.

  • No universal ATT&CK coverage score or compliance percentage.

  • No substitution for current threat intelligence, procedure analysis, detection engineering, or adversary emulation.

  • No Mobile or ICS mapping in this edition.

  • No claim that ATT&CK is a control framework or regulatory standard.

14. Maintenance and Revalidation

CRO-026 shall be reviewed after every ATT&CK major or minor release, any material GAISSF control change, new platform scope, significant threat-intelligence change, or evidence that a mapping is ambiguous or no longer operationally useful.

Annex A - Quality Assurance Record

QA check Result
GAISSF controls inventoried 59
Enterprise tactics inventoried 14
Priority techniques mapped 100
Forward mapping records 112
Reverse tactic register Completed
Enterprise/Mobile/ICS scope separated Yes
Independent threat-informed-defense review Required before final publication