Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable or Remove Feature or Program + M1045 Code Signing + M1049 Antivirus/Antimalware + M1031 Network Intrusion Prevention + M1032 Multi-factor Authentication + M1041 Encrypt Sensitive Information + M1044 Restrict Library Loading + M1046 Boot Integrity + M1047 Audit + M1048 Application Isolation and Sandboxing + M1049 Antivirus/Antimalware + M1050 Exploit Protection + M1051 Update Software + M1052 User Account Control + M1053 Data Backup + M1054 Software Configuration + M1055 Do Not Mitigate (informational) + M1057 Data Loss Prevention. Mitigation prioritisation by Technique mappings. Risk-based application using ATT&CK Navigator + CIS Controls v8 + NIST CSF 2.0 + NIST 800-53 mapping. Compensating controls where direct mitigation not feasible. Integration with vulnerability management + patch management + identity and access management + endpoint protection + network segmentation programmes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.