Cyber framework mapping skill
Maintains sparse, reviewable cybersecurity framework edges with versioned IDs, relation, rationale, source, and review status.
by HoangNguyen0403·MIT license·★ 569 Stars on the repo·GitHub ↗
Use now
npx degit HoangNguyen0403/agent-skills-standard/skills/cybersecurity/cyber-framework-mapping#develop ~/.claude/skills/cyber-framework-mappingChecked ·commit develop
Files of Cyber framework mapping
SKILL.md
Show the full text52 lines
Cyber Framework Mapping
Priority: P1 (HIGH)
Map only evidenced relationships; catalog context is not proof of efficacy, compliance, or coverage.
Structure
cyber-framework-mapping/
├── SKILL.md
├── references/edge-record.md
└── evals/evals.json
Workflow
- Name framework, version, stable ID, and exact source URL or document section.
- Choose relation (
supports,describes,observed-as,partial,unknown, orconflicts). - Write a bounded rationale tied to an evidence record, not a generic similarity.
- Set review status:
reviewed,needs-review, orunreviewed; include reviewer and date when reviewed. - Preserve empty or unknown mappings explicitly; do not infer a complete catalog.
- On a version/source change, preserve the prior versioned edge and its evidence unchanged. Create a separately versioned candidate linked to the prior record, mark it
needs-review, and re-review; never overwrite historical mappings.
Rules
- Prefer primary framework publications and official technique catalogs.
- Keep framework IDs version-qualified; never silently merge revisions.
- Separate a mapped edge from a control claim, measured efficacy, or compliance assertion.
- Link shared evidence fields for observation provenance.
For mapped observations, carry
engagement_scope_ref,skill_version,source,observed_at,finding_status,evidence_refs,limitations, andaccountable_owner.
Anti-Patterns
- No broad equivalence: One keyword does not establish a mapping.
- No version drift: Verify the current revision before reusing an ID.
- No compliance leap: Mapping never certifies a control or outcome.
- No fabricated completeness: Mark unknown edges and gaps.
References
| 1 | |
| 2 | name cyber-framework-mapping |
| 3 | guardrail true |
| 4 | description Maintains sparse, reviewable cybersecurity framework edges with versioned IDs, relation, rationale, source, and review status. Use when mapping exercise observations or procedures to NIST, ATT&CK, or another named framework. |
| 5 | metadata |
| 6 | labels [cybersecurity, framework-mapping, provenance] |
| 7 | triggers |
| 8 | keywords [framework mapping, control mapping, ATT&CK mapping, NIST mapping, framework edge, mapping review] |
| 9 | |
| 10 | # Cyber Framework Mapping |
| 11 | |
| 12 | ## **Priority: P1 (HIGH)** |
| 13 | |
| 14 | Map only evidenced relationships; catalog context is not proof of efficacy, compliance, or coverage. |
| 15 | |
| 16 | ## Structure |
| 17 | |
| 18 | |
| 19 | cyber-framework-mapping/ |
| 20 | ├── SKILL.md |
| 21 | ├── references/edge-record.md |
| 22 | └── evals/evals.json |
| 23 | |
| 24 | |
| 25 | ## Workflow |
| 26 | |
| 27 | Name framework, version, stable ID, and exact source URL or document section. |
| 28 | Choose relation (`supports`, `describes`, `observed-as`, `partial`, `unknown`, or `conflicts`). |
| 29 | Write a bounded rationale tied to an evidence record, not a generic similarity. |
| 30 | Set review status: `reviewed`, `needs-review`, or `unreviewed`; include reviewer and date when reviewed. |
| 31 | Preserve empty or unknown mappings explicitly; do not infer a complete catalog. |
| 32 | On a version/source change, preserve the prior versioned edge and its evidence unchanged. Create a separately versioned candidate linked to the prior record, mark it `needs-review`, and re-review; never overwrite historical mappings. |
| 33 | |
| 34 | ## Rules |
| 35 | |
| 36 | Prefer primary framework publications and official technique catalogs. |
| 37 | Keep framework IDs version-qualified; never silently merge revisions. |
| 38 | Separate a mapped edge from a control claim, measured efficacy, or compliance assertion. |
| 39 | Link [shared evidence fields] for observation provenance. |
| 40 | For mapped observations, carry `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `finding_status`, `evidence_refs`, `limitations`, and `accountable_owner`. |
| 41 | |
| 42 | ## Anti-Patterns |
| 43 | |
| 44 | **No broad equivalence**: One keyword does not establish a mapping. |
| 45 | **No version drift**: Verify the current revision before reusing an ID. |
| 46 | **No compliance leap**: Mapping never certifies a control or outcome. |
| 47 | **No fabricated completeness**: Mark unknown edges and gaps. |
| 48 | |
| 49 | ## References |
| 50 | |
| 51 | [Framework edge schema] |
| 52 |
Discussion
Alternatives
Browse more free Claude skills or everything in Product.