What problem does it solve?
Manually creating consistent, framework-mapped threat catalogs for cloud services in the FINOS Common Cloud Controls (CCC) standard is time-consuming and prone to errors, risking non-compliance with CCC schema requirements and incomplete mapping to standard cybersecurity frameworks.
Core Features & Use Cases
- Core Threat Reuse: Automatically imports applicable pre-defined CCC core threats to avoid duplication of generic risks.
- Service-Specific Threat Mapping: Defines unique threats for a cloud service's capabilities, grounded in real-world adversary behavior and CSP security advisories.
- Framework Alignment: Maps each threat to external standards including MITRE ATT&CK, MITRE D3FEND, CISA KEV, CWE, and OWASP, with strict gating based on declared metadata references.
- Use Case: A cloud security engineer onboarding a new IaaS service to the CCC repository can use this skill to generate a complete, schema-validated threats.yaml file that aligns with CCC standards and maps service-specific risks like misconfigured access controls to relevant MITRE ATT&CK techniques.
Quick Start
Use the build-threat-catalog skill to generate a validated threats.yaml file for the AWS S3 service catalog in the CCC repository.