Cyber framework mapping skill

Maintains sparse, reviewable cybersecurity framework edges with versioned IDs, relation, rationale, source, and review status.

by HoangNguyen0403·MIT license·★ 569 Stars on the repo·GitHub ↗

Use now

Files of Cyber framework mapping

HoangNguyen0403/develop1 file shown
SKILL.md
Show the full text52 lines
cyber-framework-mapping/SKILL.md52 lines · 2.3 KB

Cyber Framework Mapping

Priority: P1 (HIGH)

Map only evidenced relationships; catalog context is not proof of efficacy, compliance, or coverage.

Structure

cyber-framework-mapping/
├── SKILL.md
├── references/edge-record.md
└── evals/evals.json

Workflow

  1. Name framework, version, stable ID, and exact source URL or document section.
  2. Choose relation (supports, describes, observed-as, partial, unknown, or conflicts).
  3. Write a bounded rationale tied to an evidence record, not a generic similarity.
  4. Set review status: reviewed, needs-review, or unreviewed; include reviewer and date when reviewed.
  5. Preserve empty or unknown mappings explicitly; do not infer a complete catalog.
  6. On a version/source change, preserve the prior versioned edge and its evidence unchanged. Create a separately versioned candidate linked to the prior record, mark it needs-review, and re-review; never overwrite historical mappings.

Rules

  • Prefer primary framework publications and official technique catalogs.
  • Keep framework IDs version-qualified; never silently merge revisions.
  • Separate a mapped edge from a control claim, measured efficacy, or compliance assertion.
  • Link shared evidence fields for observation provenance. For mapped observations, carry engagement_scope_ref, skill_version, source, observed_at, finding_status, evidence_refs, limitations, and accountable_owner.

Anti-Patterns

  • No broad equivalence: One keyword does not establish a mapping.
  • No version drift: Verify the current revision before reusing an ID.
  • No compliance leap: Mapping never certifies a control or outcome.
  • No fabricated completeness: Mark unknown edges and gaps.

References

1---
2name: cyber-framework-mapping
3guardrail: true
4description: Maintains sparse, reviewable cybersecurity framework edges with versioned IDs, relation, rationale, source, and review status. Use when mapping exercise observations or procedures to NIST, ATT&CK, or another named framework.
5metadata:
6 labels: [cybersecurity, framework-mapping, provenance]
7 triggers:
8 keywords: [framework mapping, control mapping, ATT&CK mapping, NIST mapping, framework edge, mapping review]
9---
10# Cyber Framework Mapping
11 
12## **Priority: P1 (HIGH)**
13 
14Map only evidenced relationships; catalog context is not proof of efficacy, compliance, or coverage.
15 
16## Structure
17 
18```text
19cyber-framework-mapping/
20├── SKILL.md
21├── references/edge-record.md
22└── evals/evals.json
23```
24 
25## Workflow
26 
271. Name framework, version, stable ID, and exact source URL or document section.
282. Choose relation (`supports`, `describes`, `observed-as`, `partial`, `unknown`, or `conflicts`).
293. Write a bounded rationale tied to an evidence record, not a generic similarity.
304. Set review status: `reviewed`, `needs-review`, or `unreviewed`; include reviewer and date when reviewed.
315. Preserve empty or unknown mappings explicitly; do not infer a complete catalog.
326. On a version/source change, preserve the prior versioned edge and its evidence unchanged. Create a separately versioned candidate linked to the prior record, mark it `needs-review`, and re-review; never overwrite historical mappings.
33 
34## Rules
35 
36- Prefer primary framework publications and official technique catalogs.
37- Keep framework IDs version-qualified; never silently merge revisions.
38- Separate a mapped edge from a control claim, measured efficacy, or compliance assertion.
39- Link [shared evidence fields](../cyber-evidence/SKILL.md) for observation provenance.
40For mapped observations, carry `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `finding_status`, `evidence_refs`, `limitations`, and `accountable_owner`.
41 
42## Anti-Patterns
43 
44- **No broad equivalence**: One keyword does not establish a mapping.
45- **No version drift**: Verify the current revision before reusing an ID.
46- **No compliance leap**: Mapping never certifies a control or outcome.
47- **No fabricated completeness**: Mark unknown edges and gaps.
48 
49## References
50 
51- [Framework edge schema](references/edge-record.md)
52 

Discussion

Alternatives