What problem does it solve?
It turns a list of identified threats into actionable security control mapping, making it easier to plan mitigations, prioritize investments, and verify control coverage.
Core Features & Use Cases
- Threat-to-Control Mapping: Connect threats (e.g., STRIDE categories) to preventive, detective, and corrective security controls.
- Defense-in-Depth Coverage: Evaluate whether mitigations span multiple control layers (Network, Application, Data, Endpoint, Process).
- Control Effectiveness & Gap Detection: Compute coverage scores based on implementation and effectiveness, then flag gaps (low coverage, missing depth, missing diversity).
- Roadmap & Reporting Templates: Generate mitigation roadmaps and structured reports to support remediation planning and validation.
Example use case: When you identify threats during a security architecture review, use this skill to map each threat to candidate controls, quantify coverage, identify weak areas, and produce a prioritized remediation plan for the next investment cycle.
Quick Start
Use the 0174-threat-mitigation-mapping skill to generate a mitigation mapping and gaps report from your threat list and candidate security controls.