tachi-control-analysis

Explain compensating-controls analysis concepts for threat-modeling workflows.

86|21|Updated Mar 21, 2026
One-click install
npx skills add https://github.com/davidmatousek/tachi --skill tachi-control-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tachi-control-analysis
Source: https://github.com/davidmatousek/tachi/tree/main/.claude/skills/tachi-control-analysis
Command: npx skills add https://github.com/davidmatousek/tachi --skill tachi-control-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Domain knowledge for compensating-controls analysis to guide detection, evaluation, and remediation planning.

Core Features & Use Cases

  • Defines the 8 compensating control categories and their STRIDE/AI mappings
  • Specifies evidence criteria, confidence levels, and residual-risk concepts for Phase 4/5
  • Provides remediation templates and a reference framework for risk scoring and recommendations

Quick Start

Explain compensating-controls domain knowledge to support threat-modeling workflows.

Frequently Asked Questions about tachi-control-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are compensating controls in threat modeling?

Compensating controls in threat modeling are security mechanisms mapped to STRIDE categories that mitigate threats. This framework defines 8 control categories with specific mappings to evaluate residual risk and guide remediation planning.

How do I map STRIDE threats to security controls?

Map STRIDE threats to security controls using the defined STRIDE-to-control mappings across 8 compensating control categories. This enables systematic detection, mapping, and scoring to determine residual risk and confidence levels for each threat scenario.

How do I calculate residual risk after applying compensating controls?

Calculate residual risk by evaluating compensating controls against evidence criteria and confidence levels during Phase 4 classification. The framework provides risk scoring templates to quantify remaining risk after control application.

What evidence is needed to validate compensating controls in risk analysis?

Validating compensating controls in risk analysis requires evidence collected according to specified evidence collection rules and confidence levels. The framework defines criteria for what constitutes sufficient evidence to support control effectiveness claims.

Can I use this compensating controls framework for software project threat modeling?

Yes, this compensating controls framework is specifically applied to software project threat modeling. It provides Phase 4 classification and Phase 5 remediation templates designed for detecting, mapping, and scoring controls within software development workflows.

How do I generate remediation guidance for failed security controls?

Generate remediation guidance using the Phase 5 remediation templates provided by the framework. These templates translate residual risk calculations and control gap analysis into actionable recommendations for addressing identified weaknesses.