Home/Compliance
iso-27001-2022

ISO 27001:2022. Security Controls

93 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
93
Total controls
0%
Detection coverage
0
Covered controls
93
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Showing gaps only ×
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A iso-27001-2022 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

63 shown of 93
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Organizational framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
A.6.1 medium
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family People framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Physical framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
A.8.15 medium
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family Technological framework iso-27001-2022
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
Showing 1-80 of 93
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin