Framework overlap

Does API 1164 cover MITRE ATT&CK?

You hold API 1164 and have been told to do MITRE ATT&CK. Here is how much overlaps, control by control.

75% of MITRE ATT&CK you already have

API 1164 already covers about 75% of MITRE ATT&CK, leaving 2 of 8 controls as genuinely new work.

Already covered 3 Likely covered 3 New work 2

What is genuinely new work

Nothing in API 1164 reaches these. This is the list to scope.

MITRE-ATTACK-Integration-Engenuity-Evaluations-CALDERA-NIST-CSF-CIS-Lockheed-Kill-Chain-Diamond-Model-STIX-TAXII
MITRE ATT&CK Integration + MITRE Engenuity + ATT&CK Evaluations + CALDERA + NIST CSF + CIS + STIX + TAXII
MITRE-ATTACK-Threat-Groups-Software-APT28-APT29-APT38-APT41-FIN7-Conti-LockBit-Lazarus-Cobalt-Strike-Mimikatz
MITRE ATT&CK Threat Groups + Software + APT28 + APT29 + APT41 + FIN7 + Conti + Lazarus + Cobalt Strike + Mimikatz
Show the 6 you already have
MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering
MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + Splunk + KQL + Yara + Snort + SIEM + Hunt
MITRE-ATTACK-Matrices-Enterprise-Mobile-ICS-Cloud-AWS-Azure-Google-Office-365-Container-Platform-Specific
MITRE ATT&CK Matrices + Enterprise + Mobile + ICS + Cloud + AWS + Azure + Google + Office 365 + Container
MITRE-ATTACK-Techniques-Sub-Techniques-200-600-T1078-T1059-T1566-T1190-T1486-Procedures-Adversary-Behaviour
MITRE ATT&CK Techniques + 200+ + Sub-Techniques + 600+ + T1078 + T1059 + T1566 + T1190 + T1486 + Procedures
MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation
MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control
MITRE-ATTACK-Scope-Adversarial-Tactics-Techniques-MITRE-Corporation-2013-v15-v16-Enterprise-Mobile-ICS-Cloud
MITRE ATT&CK Scope + MITRE Corporation 2013 + v15 + v16 + Enterprise + Mobile + ICS + Cloud + Container
MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact
MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact

How this is calculated

Already covered means a mapping runs from a control in API 1164 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition