Use when mapping identified threats to security controls: prioritizing security spend, remediation roadmaps or validating control coverage. Covers preventive, detective and corrective controls across network, app, data, endpoint and process layers. For writing detections see threat-detection.
Pro scans all 3 files and shows the line behind each finding
Scanned 9/28/2026
npx -y skills add monoes/monomind --skill threat-mitigation-mapping --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Threat Mitigation Mapping?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/monoes-threat-mitigation-mapping)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: threat-mitigation-mapping
description: "Use when mapping identified threats to security controls: prioritizing security spend, remediation roadmaps or validating control coverage. Covers preventive, detective and corrective controls across network, app, data, endpoint and process layers. For writing detections see threat-detection."
tags: ["security","architecture","planning"]
tools: []
license: MIT
source: https://github.com/wshobson/agents
source_path: "plugins/security-scanning/skills/threat-mitigation-mapping"
source_commit: 4236bb91f8395b0435f1d8b8baf9e8e4c69a8620
---
# Threat Mitigation Mapping
Connect threats to controls for effective security planning.
## When to Use This Skill
- Prioritizing security investments
- Creating remediation roadmaps
- Validating control coverage
- Designing defense-in-depth
- Security architecture review
- Risk treatment planning
## Core Concepts
### 1. Control Categories
```
Preventive ────► Stop attacks before they occur
│ (Firewall, Input validation)
│
Detective ─────► Identify attacks in progress
│ (IDS, Log monitoring)
│
Corrective ────► Respond and recover from attacks
(Incident response, Backup restore)
```
### 2. Control Layers
| Layer | Examples |
| --------------- | ------------------------------------ |
| **Network** | Firewall, WAF, DDoS protection |
| **Application** | Input validation, authentication |
| **Data** | Encryption, access controls |
| **Endpoint** | EDR, patch management |
| **Process** | Security training, incident response |
### 3. Defense in Depth
```
┌──────────────────────┐
│ Perimeter │ ← Firewall, WAF
│ ┌──────────────┐ │
│ │ Network │ │ ← Segmentation, IDS
│ │ ┌────────┐ │ │
│ │ │ Host │ │ │ ← EDR, Hardening
│ │ │ ┌────┐ │ │ │
│ │ │ │App │ │ │ │ ← Auth, Validation
│ │ │ │Data│ │ │ │ ← Encryption
│ │ │ └────┘ │ │ │
│ │ └────────┘ │ │
│ └──────────────┘ │
└──────────────────────┘
```
## Templates and detailed worked examples
Full template library and detailed mitigation/control mappings live in `references/details.md`. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.
## Best Practices
### Do's
- **Map all threats** - No threat should be unmapped
- **Layer controls** - Defense in depth is essential
- **Mix control types** - Preventive, detective, corrective
- **Track effectiveness** - Measure and improve
- **Review regularly** - Controls degrade over time
### Don'ts
- **Don't rely on single controls** - Single points of failure
- **Don't ignore cost** - ROI matters
- **Don't skip testing** - Untested controls may fail
- **Don't set and forget** - Continuous improvement
- **Don't ignore people/process** - Technology alone isn't enough
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!