GAISSF to MITRE ATTACK Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to MITRE ATTACK, with scope, method, limitations and traceability.
1. Executive Summary
CRO-026 documents defensive relationships between all 59 GAISSF v1.0 controls and a source-bounded priority set of 100 MITRE ATT&CK Enterprise techniques across all 14 Enterprise tactics. The register contains 112 control-to-technique mapping records and a reverse tactic-level coverage view.
The crosswalk supports threat modelling, detection and telemetry planning, adversary-emulation scoping, evidence reuse, and assurance design. It does not convert ATT&CK into a compliance checklist and does not prove that any mapped technique is prevented, detected, or mitigated in operation.
2. Purpose and Intended Use
Translate adversary behavior into GAISSF control and evidence requirements.
Support SOC, threat-intelligence, red-team, purple-team, architecture, and assurance collaboration.
Identify control, telemetry, detection, resilience, and testing gaps.
Provide a repeatable source for GitHub, automation, and assessment tooling.
3. Scope
Primary scope: MITRE ATT&CK Enterprise v19. Mobile and ICS are excluded from this edition because their techniques, platforms, operational consequences, and evidence expectations require separate controlled profiles. The official ATT&CK dataset remains authoritative for the complete current technique, sub-technique, procedure, mitigation, detection-strategy, group, software, and campaign inventory.
4. Source Baseline
| Source | Version / status | Use in CRO-026 |
|---|---|---|
| GAISSF Framework Standard | GAISSF-NOR-001 v1.0, normative | Architecture, conformance language and source authority |
| GAISSF Control Catalogue | GAISSF-NOR-004 v1.0, normative | Authoritative 59-control baseline |
| MITRE ATT&CK | Version 19, released 28 April 2026 | Enterprise tactics and technique identifiers |
| ATT&CK STIX Data | Official MITRE GitHub repository | Machine-readable source and future revalidation |
5. Mapping Methodology
Map substantive defensive outcomes, not labels.
Use technique-level records; sub-technique and procedure analysis remains contextual.
Separate relationship strength from confidence.
Treat multiple GAISSF controls supporting one ATT&CK behavior as composite coverage.
Record residual gaps for telemetry, procedure analysis, threat relevance, emulation, and operating effectiveness.
Perform reverse tactic coverage to identify silent omissions.
6. Controlled Vocabulary
| Code | Meaning |
|---|---|
| E | Equivalent or near-equivalent; exceptional threshold |
| SP | Strong partial |
| P | Partial |
| S | Supporting |
| C | Contextual |
| N | No material mapping |
| O | Outside scope |
| U | Unable to determine |
7. Enterprise Tactic Coverage
| Tactic ID | Tactic | Mapped controls | Coverage | Confidence |
|---|---|---|---|---|
| TA0043 | Reconnaissance | 10 | Substantially Addressed | Medium-High |
| TA0042 | Resource Development | 8 | Substantially Addressed | Medium-High |
| TA0001 | Initial Access | 32 | Substantially Addressed | Medium-High |
| TA0002 | Execution | 5 | Partially Addressed | Medium |
| TA0003 | Persistence | 10 | Substantially Addressed | Medium-High |
| TA0004 | Privilege Escalation | 1 | Partially Addressed | Medium |
| TA0005 | Defense Evasion | 9 | Substantially Addressed | Medium-High |
| TA0006 | Credential Access | 1 | Partially Addressed | Medium |
| TA0007 | Discovery | 2 | Partially Addressed | Medium |
| TA0008 | Lateral Movement | 2 | Partially Addressed | Medium |
| TA0009 | Collection | 1 | Partially Addressed | Medium |
| TA0011 | Command and Control | 0 | Not Addressed | Not Rated |
| TA0010 | Exfiltration | 6 | Partially Addressed | Medium |
| TA0040 | Impact | 12 | Substantially Addressed | Medium-High |
8. Function-by-Function Analysis
TA0043 - Reconnaissance
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-04, D3-CTL-05, D7-CTL-H01, D7-CTL-H02, D7-CTL-H04, D8-CTL-01, D8-CTL-02, D8-CTL-03, D8-CTL-04, D8-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0042 - Resource Development
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-07, D6-CTL-06, D8-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0001 - Initial Access
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-06, D1-CTL-07, D1-CTL-08, D1-CTL-09, D2-CTL-01, D2-CTL-03, D2-CTL-05, D3-CTL-01, D3-CTL-02, D3-CTL-03, D3-CTL-06, D3-CTL-07, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07, D6-CTL-03, D6-CTL-05, D6-CTL-06, D7-CTL-H01, D7-CTL-H05, D9-CTL-03, D9-CTL-04, D9-CTL-05. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0002 - Execution
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D2-CTL-04, D2-CTL-05, D2-CTL-06, D3-CTL-04, D7-CTL-H02. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0003 - Persistence
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D1-CTL-01, D1-CTL-02, D1-CTL-03, D1-CTL-04, D1-CTL-05, D1-CTL-07, D1-CTL-08, D1-CTL-09, D6-CTL-01, D6-CTL-04. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0004 - Privilege Escalation
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D7-CTL-H03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0005 - Defense Evasion
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-01, D2-CTL-06, D3-CTL-02, D3-CTL-03, D3-CTL-04, D3-CTL-05, D3-CTL-07, D6-CTL-02, D9-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0006 - Credential Access
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D7-CTL-H03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0007 - Discovery
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D4-CTL-06, D6-CTL-02. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0008 - Lateral Movement
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D3-CTL-01, D3-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0009 - Collection
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D2-CTL-03. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0011 - Command and Control
Coverage assessment: Not Addressed (Not Rated confidence). Mapped GAISSF controls: None. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0010 - Exfiltration
Coverage assessment: Partially Addressed (Medium confidence). Mapped GAISSF controls: D9-CTL-01, D9-CTL-02, D9-CTL-03, D9-CTL-04, D9-CTL-05, D9-CTL-06. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
TA0040 - Impact
Coverage assessment: Substantially Addressed (Medium-High confidence). Mapped GAISSF controls: D2-CTL-02, D5-CTL-01, D5-CTL-02, D5-CTL-03, D5-CTL-04, D5-CTL-05, D5-CTL-06, D6-CTL-07, D8-CTL-04, D9-CTL-01, D9-CTL-02, D9-CTL-07. ATT&CK procedure coverage, platform-specific detections, threat-actor relevance, and validated telemetry are outside a framework-level crosswalk.
9. Priority Technique Inventory
| Technique ID | Technique | Tactic |
|---|---|---|
| T1595 | Active Scanning | Reconnaissance |
| T1592 | Gather Victim Host Information | Reconnaissance |
| T1589 | Gather Victim Identity Information | Reconnaissance |
| T1590 | Gather Victim Network Information | Reconnaissance |
| T1591 | Gather Victim Org Information | Reconnaissance |
| T1593 | Search Open Websites/Domains | Reconnaissance |
| T1594 | Search Victim-Owned Websites | Reconnaissance |
| T1596 | Search Open Technical Databases | Reconnaissance |
| T1583 | Acquire Infrastructure | Resource Development |
| T1584 | Compromise Infrastructure | Resource Development |
| T1585 | Establish Accounts | Resource Development |
| T1586 | Compromise Accounts | Resource Development |
| T1587 | Develop Capabilities | Resource Development |
| T1588 | Obtain Capabilities | Resource Development |
| T1608 | Stage Capabilities | Resource Development |
| T1189 | Drive-by Compromise | Initial Access |
| T1190 | Exploit Public-Facing Application | Initial Access |
| T1133 | External Remote Services | Initial Access |
| T1566 | Phishing | Initial Access |
| T1195 | Supply Chain Compromise | Initial Access |
| T1078 | Valid Accounts | Initial Access |
| T1059 | Command and Scripting Interpreter | Execution |
| T1203 | Exploitation for Client Execution | Execution |
| T1204 | User Execution | Execution |
| T1047 | Windows Management Instrumentation | Execution |
| T1129 | Shared Modules | Execution |
| T1106 | Native API | Execution |
| T1053 | Scheduled Task/Job | Execution |
| T1127 | Trusted Developer Utilities Proxy Execution | Execution |
| T1098 | Account Manipulation | Persistence |
| T1547 | Boot or Logon Autostart Execution | Persistence |
| T1136 | Create Account | Persistence |
| T1505 | Server Software Component | Persistence |
| T1525 | Implant Internal Image | Persistence |
| T1554 | Compromise Host Software Binary | Persistence |
| T1053.003 | Scheduled Task/Job: Cron | Persistence |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
| T1548 | Abuse Elevation Control Mechanism | Privilege Escalation |
| T1134 | Access Token Manipulation | Privilege Escalation |
| T1484 | Domain or Tenant Policy Modification | Privilege Escalation |
| T1027 | Obfuscated Files or Information | Defense Evasion |
| T1070 | Indicator Removal | Defense Evasion |
| T1036 | Masquerading | Defense Evasion |
| T1562 | Impair Defenses | Defense Evasion |
| T1553 | Subvert Trust Controls | Defense Evasion |
| T1218 | System Binary Proxy Execution | Defense Evasion |
| T1222 | File and Directory Permissions Modification | Defense Evasion |
| T1497 | Virtualization/Sandbox Evasion | Defense Evasion |
| T1574 | Hijack Execution Flow | Defense Evasion |
| T1110 | Brute Force | Credential Access |
| T1555 | Credentials from Password Stores | Credential Access |
| T1552 | Unsecured Credentials | Credential Access |
| T1003 | OS Credential Dumping | Credential Access |
| T1528 | Steal Application Access Token | Credential Access |
| T1539 | Steal Web Session Cookie | Credential Access |
| T1649 | Steal or Forge Authentication Certificates | Credential Access |
| T1621 | Multi-Factor Authentication Request Generation | Credential Access |
| T1087 | Account Discovery | Discovery |
| T1580 | Cloud Infrastructure Discovery | Discovery |
| T1613 | Container and Resource Discovery | Discovery |
| T1526 | Cloud Service Discovery | Discovery |
| T1083 | File and Directory Discovery | Discovery |
| T1049 | System Network Connections Discovery | Discovery |
| T1018 | Remote System Discovery | Discovery |
| T1518 | Software Discovery | Discovery |
| T1482 | Domain Trust Discovery | Discovery |
| T1614 | System Location Discovery | Discovery |
| T1021 | Remote Services | Lateral Movement |
| T1570 | Lateral Tool Transfer | Lateral Movement |
| T1210 | Exploitation of Remote Services | Lateral Movement |
| T1550 | Use Alternate Authentication Material | Lateral Movement |
| T1119 | Automated Collection | Collection |
| T1213 | Data from Information Repositories | Collection |
| T1530 | Data from Cloud Storage | Collection |
| T1114 | Email Collection | Collection |
| T1005 | Data from Local System | Collection |
| T1074 | Data Staged | Collection |
| T1560 | Archive Collected Data | Collection |
| T1056 | Input Capture | Collection |
| T1071 | Application Layer Protocol | Command and Control |
| T1105 | Ingress Tool Transfer | Command and Control |
| T1090 | Proxy | Command and Control |
| T1219 | Remote Access Software | Command and Control |
| T1572 | Protocol Tunneling | Command and Control |
| T1102 | Web Service | Command and Control |
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
| T1567 | Exfiltration Over Web Service | Exfiltration |
| T1537 | Transfer Data to Cloud Account | Exfiltration |
| T1020 | Automated Exfiltration | Exfiltration |
| T1041 | Exfiltration Over C2 Channel | Exfiltration |
| T1052 | Exfiltration Over Physical Medium | Exfiltration |
| T1486 | Data Encrypted for Impact | Impact |
| T1485 | Data Destruction | Impact |
| T1490 | Inhibit System Recovery | Impact |
| T1498 | Network Denial of Service | Impact |
| T1499 | Endpoint Denial of Service | Impact |
| T1565 | Data Manipulation | Impact |
| T1531 | Account Access Removal | Impact |
| T1529 | System Shutdown/Reboot | Impact |
| T1657 | Financial Theft | Impact |
10. Detailed Mapping Register
| Record | GAISSF control | ATT&CK technique | Tactic | Rel. | Conf. |
|---|---|---|---|---|---|
| CRO026-MAP-0001 | D1-CTL-01 Dataset Provenance & Poisoning Prevention | T1195 Supply Chain Compromise | Initial Access | S | Low |
| CRO026-MAP-0002 | D1-CTL-01 Dataset Provenance & Poisoning Prevention | T1554 Compromise Host Software Binary | Persistence | S | Low |
| CRO026-MAP-0003 | D1-CTL-02 Model Extraction Resistance | T1195 Supply Chain Compromise | Initial Access | S | Low |
| CRO026-MAP-0004 | D1-CTL-02 Model Extraction Resistance | T1554 Compromise Host Software Binary | Persistence | S | Low |
| CRO026-MAP-0005 | D1-CTL-03 Behavioral Drift Detection | T1195 Supply Chain Compromise | Initial Access | S | Low |
| CRO026-MAP-0006 | D1-CTL-03 Behavioral Drift Detection | T1554 Compromise Host Software Binary | Persistence | S | Low |
11. Evidence Reuse Guidance
Threat models, attack-path models, architecture diagrams and trust-boundary records.
Identity, access, secrets, privileged-access and service-account evidence.
Secure development, dependency, build, image and supplier assurance records.
Logging, telemetry, detection, alert triage and incident-response evidence.
Backup, restoration, resilience, denial-of-service and recovery test records.
Red-team, purple-team, penetration-test and adversary-emulation evidence.
12. Limitations
ATT&CK describes adversary behavior and is not a prescriptive control or compliance framework.
A mapping does not prove prevention, detection, mitigation effectiveness, or test coverage.
The priority technique inventory is scoped to Enterprise techniques with direct relevance to GAISSF and does not replace the complete official ATT&CK dataset.
Sub-techniques and procedures require environment-specific analysis.
Mobile and ICS domains are excluded from this edition and require separate controlled profiles.
ATT&CK changes require source revalidation.
13. Notably Absent
No MITRE endorsement, approval, certification, or recognition.
No claim of complete prevention or detection of an ATT&CK technique.
No universal ATT&CK coverage score or compliance percentage.
No substitution for current threat intelligence, procedure analysis, detection engineering, or adversary emulation.
No Mobile or ICS mapping in this edition.
No claim that ATT&CK is a control framework or regulatory standard.
14. Maintenance and Revalidation
CRO-026 shall be reviewed after every ATT&CK major or minor release, any material GAISSF control change, new platform scope, significant threat-intelligence change, or evidence that a mapping is ambiguous or no longer operationally useful.
Annex A - Quality Assurance Record
| QA check | Result |
|---|---|
| GAISSF controls inventoried | 59 |
| Enterprise tactics inventoried | 14 |
| Priority techniques mapped | 100 |
| Forward mapping records | 112 |
| Reverse tactic register | Completed |
| Enterprise/Mobile/ICS scope separated | Yes |
| Independent threat-informed-defense review | Required before final publication |