threat-mitigation-mapping
wshobson/agents
Map threats to security controls and mitigations for effective defense planning.
What is threat-mitigation-mapping?
This skill connects identified security threats to appropriate preventive, detective, and corrective controls across network, application, data, endpoint, and process layers. Use it when prioritizing security investments, building remediation roadmaps, validating control coverage, or designing defense-in-depth architectures.
- Map threats to preventive, detective, and corrective control types
- Organize controls across five layers: network, application, data, endpoint, and process
- Design defense-in-depth strategies with layered controls
- Validate control coverage against identified threats
- Create security investment prioritization frameworks
- Support risk treatment and remediation planning
How to install threat-mitigation-mapping
npx skills add https://github.com/wshobson/agents --skill threat-mitigation-mappingHow to use threat-mitigation-mapping
- 1.Identify and list all threats relevant to your environment or system
- 2.Categorize each threat by attack phase (prevention, detection, response needed)
- 3.Map each threat to appropriate controls across the five layers
- 4.Evaluate control types: ensure mix of preventive, detective, and corrective
- 5.Assess layering: verify defense-in-depth with multiple controls per threat
- 6.Prioritize based on threat severity and control cost/feasibility
- 7.Document coverage gaps and create implementation roadmap
- 8.Review and update mappings regularly as threats and controls evolve
Use cases
- Prioritizing which security controls to invest in first based on threat landscape
- Creating a remediation roadmap that addresses gaps in control coverage
- Validating that existing controls effectively mitigate identified threats
- Designing a defense-in-depth architecture for a critical application
- Reviewing security architecture to ensure no single point of failure
- Security architects
- Risk and compliance managers
- CISO and security leadership
- Incident response teams
- Security engineers planning control implementations
threat-mitigation-mapping FAQ
Preventive controls stop attacks before they occur (e.g., firewall, input validation). Detective controls identify attacks in progress (e.g., IDS, log monitoring). Corrective controls respond and recover from attacks (e.g., incident response, backup restore). Effective security uses all three types.
Defense-in-depth uses multiple layered controls so that if one fails, others still protect you. Relying on a single control creates a single point of failure. Layering across network, application, data, endpoint, and process ensures comprehensive coverage.
Track and measure control effectiveness over time. Test controls to ensure they work as designed. Review regularly because controls degrade—patches lapse, configurations drift, and threats evolve. Continuous improvement is essential.
No. While prevention is ideal, detective and corrective controls are equally important. Attackers will eventually get through some preventive measures, so you need to detect breaches quickly and respond effectively. A balanced mix is critical.
Consider threat severity, control cost, and feasibility. Start with high-impact threats and controls that provide broad coverage. Use the mitigation model templates in references/details.md to score and rank options systematically.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: threat-mitigation-mapping description: Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
Threat Mitigation Mapping
Connect threats to controls for effective security planning.
When to Use This Skill
- Prioritizing security investments
- Creating remediation roadmaps
- Validating control coverage
- Designing defense-in-depth
- Security architecture review
- Risk treatment planning
Core Concepts
1. Control Categories
Preventive ────► Stop attacks before they occur
│ (Firewall, Input validation)
│
Detective ─────► Identify attacks in progress
│ (IDS, Log monitoring)
│
Corrective ────► Respond and recover from attacks
(Incident response, Backup restore)
2. Control Layers
| Layer | Examples |
|---|---|
| Network | Firewall, WAF, DDoS protection |
| Application | Input validation, authentication |
| Data | Encryption, access controls |
| Endpoint | EDR, patch management |
| Process | Security training, incident response |
3. Defense in Depth
┌──────────────────────┐
│ Perimeter │ ← Firewall, WAF
│ ┌──────────────┐ │
│ │ Network │ │ ← Segmentation, IDS
│ │ ┌────────┐ │ │
│ │ │ Host │ │ │ ← EDR, Hardening
│ │ │ ┌────┐ │ │ │
│ │ │ │App │ │ │ │ ← Auth, Validation
│ │ │ │Data│ │ │ │ ← Encryption
│ │ │ └────┘ │ │ │
│ │ └────────┘ │ │
│ └──────────────┘ │
└──────────────────────┘
Templates and detailed worked examples
Full template library and detailed mitigation/control mappings live in references/details.md. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.
Best Practices
Do's
- Map all threats - No threat should be unmapped
- Layer controls - Defense in depth is essential
- Mix control types - Preventive, detective, corrective
- Track effectiveness - Measure and improve
- Review regularly - Controls degrade over time
Don'ts
- Don't rely on single controls - Single points of failure
- Don't ignore cost - ROI matters
- Don't skip testing - Untested controls may fail
- Don't set and forget - Continuous improvement
- Don't ignore people/process - Technology alone isn't enough
Related skills
More from wshobson/agents and the wider catalog.

trace-to-training-data
Convert graded evaluation traces into SFT examples and DPO preference pairs for model training.

track-management
Create and manage Conductor tracks—logical work units for features, bugs, and refactors.

turborepo-caching
Configure Turborepo for efficient monorepo builds with local and remote caching.

typescript-advanced-types
Master TypeScript's advanced type system: generics, conditional types, mapped types, and utility types for type-safe applications.

unity-ecs-patterns
Reference patterns and best practices for high-performance Unity DOTS, ECS, Jobs, and Burst development.

uv-package-manager
Ultra-fast Python package manager and virtual environment tool—10-100x faster than pip with built-in dependency resolution and Python version management.