️ MITRE ATLAS · Controls Mapping · Compliance · Free Tool

MITRE Security Mapping Tool™: Map Your Security Controls to Real AI Threats (2026)

Most security teams know which controls they have. Very few know which MITRE ATLAS AI threats those controls actually cover — and which ones they don't. The Security Mapping Tool™ closes that gap: select your controls, get your threat coverage, see your compliance gaps, find your blind spots, and export everything to CSV.

️ MITRE Security Mapping Tool™ — Map Your Controls Now

Select your AI systems and security controls. Get 5 result views: coverage overview, gap analysis, compliance mapping, vendor recommendations, and coverage matrix. Free CSV export.

Why Controls Mapping Matters

The standard approach to AI security is additive: implement controls, accumulate them over time, and assume coverage improves. The problem is that AI security controls aren't uniformly distributed across the threat landscape. Most organisations end up with multiple overlapping controls for prompt injection (the most visible threat) and zero controls for agent tool governance, RAG access control, and AI supply chain security (the fastest-growing threat categories).

Without explicit mapping from controls to threats, this imbalance is invisible. An organisation might have 15 security controls that collectively cover 6 MITRE ATLAS techniques — while 30+ other techniques remain completely uncovered. The Security Mapping Tool makes this visible, so investment decisions become rational rather than reactive.

The 5 Result Views

Overview

Risk-weighted coverage score, coverage by ATLAS threat category, and executive summary narrative

Gap Analysis

Uncovered techniques with risk severity, blind spot identification, "what-if" investment simulation, and prioritised recommendations

Compliance

Coverage mapped to SOC 2, ISO 27001, NIST AI RMF, and EU AI Act — with specific gap identification per framework

Vendors

Product recommendations mapped to your specific gaps — tools most likely to improve your coverage score

Coverage Matrix

Visual grid of controls vs ATLAS techniques — heat-mapped to show where coverage is concentrated and where it's absent

Compliance Framework Mappings

A key differentiator of the Security Mapping Tool is its compliance output. Most AI security tools tell you your coverage against threats. This tool also tells you what that coverage means for your compliance obligations.

SOC 2

Maps controls to Trust Services Criteria: Security (CC6-CC9), Availability (A1), and Confidentiality (C1).

  • CC6.1 — Logical and physical access controls
  • CC6.6 — Logical access to assets
  • CC7.2 — System monitoring controls
  • CC8.1 — Change management

ISO 27001:2022

Maps to Annex A controls as they apply to AI systems and LLM deployments.

  • A.8.20 — Network security controls
  • A.8.23 — Web filtering (prompt filtering)
  • A.8.28 — Secure coding (AI supply chain)
  • A.5.23 — Information security for cloud services

️ NIST AI RMF

Maps to Govern, Map, Measure, and Manage functions for AI risk management.

  • GOVERN 1.1 — AI risk policies
  • MAP 1.1 — Risk context identification
  • MEASURE 2.2 — AI risk evaluation
  • MANAGE 1.3 — Response and recovery

🇪🇺 EU AI Act

Maps to technical and governance requirements for high-risk AI systems under the EU AI Act.

  • Art. 9 — Risk management system
  • Art. 13 — Transparency requirements
  • Art. 14 — Human oversight controls
  • Art. 15 — Accuracy and robustness

The Most Common Control Gaps the Tool Finds

1

No LLM-specific prompt injection detection

General input validation exists but wasn't designed for semantic prompt attacks. Standard WAFs and input sanitisation detect SQL injection and XSS but are blind to "ignore previous instructions" variants. Gap: AML.T0051, AML.T0054 partially uncovered despite existing controls.

2

No agent tool permission governance

IAM controls manage human access to systems. They don't govern which tools AI agents can call, with what permissions, or under what conditions. Most organisations have zero formal control over agent tool scope. Gap: AML.T0080, AML.T0090 completely uncovered.

3

Data access controls not applied at RAG retrieval layer

Data access controls govern who can read files and databases. They don't automatically apply to which chunks get retrieved from a vector database. A user authorised to read a document category may still receive retrieval results from restricted documents. Gap: cross-tenant leakage techniques uncovered despite strong underlying data controls.

4

General monitoring doesn't capture AI-specific signals

SIEM, logging, and anomaly detection capture network events, authentication events, and file access events. They don't capture prompt anomalies, output anomalies, agent behaviour deviations, or retrieval scope violations. Gap: runtime monitoring ATLAS techniques uncovered despite substantial general monitoring investment.

5

Third-party risk process not extended to AI vendors

Vendor risk management assesses financial stability, SLAs, and general security posture. It rarely evaluates AI-specific criteria: training data terms, model behaviour, inference security, or model version change management. Gap: supply chain ATLAS techniques largely uncovered despite mature vendor risk programme.

Who Should Use the Mapping Tool?

️

Security Architects

Validate that your AI security architecture actually covers the ATLAS techniques you think it does — and identify the architectural gaps before they become incidents

Compliance Teams

Map existing controls to SOC 2, ISO 27001, NIST AI RMF, and EU AI Act in minutes — identify specific gaps per framework without manual cross-reference work

CISOs & Security Leaders

Use the "what-if" investment simulation to model the coverage impact of specific control investments before budget requests — justify spend with data, not intuition

Red Teams & Pen Testers

Use blind spot analysis to identify the ATLAS techniques most likely to succeed against your current control stack — focus your testing where defences are weakest

Coverage Matrix — See Everything at Once

The visual coverage matrix shows all your controls against all MITRE ATLAS techniques in a single heat-mapped grid. Instantly see where coverage clusters and where the gaps are.

Frequently Asked Questions

What does "overlap detection" mean?
Overlap detection flags when two or more of your selected controls mitigate the same MITRE ATLAS technique. This matters for budget optimisation — if you're considering a new control that covers threats already addressed by two existing controls, the overlap panel shows this redundancy so you can redirect that investment to actual gaps. Many organisations discover they're triple-covered on prompt injection while having zero coverage on agent governance.
Can I export my mapping results?
Yes — the tool includes CSV export covering your control-to-technique mappings, coverage percentages, gap analysis, and prioritised recommendations. The CSV is structured for import into spreadsheets, risk registers, or GRC tools. For PDF output, use the browser print function (Ctrl+P) which renders the styled results view.
What does the "what-if" simulation do?
The gap analysis tab includes an investment simulation: select any uncovered control and the tool immediately shows the coverage impact — which ATLAS techniques would be addressed, the percentage coverage gain, and where that would place you in the risk weighting. This makes control investment decisions data-driven: "adding AI-specific runtime monitoring would close 8 ATLAS techniques and improve our coverage by 14%."
How does this differ from the Coverage Calculator?
The Coverage Calculator measures your current coverage level across the full ATLAS framework in 3 steps — it answers "how much of ATLAS are we covered against?" The Security Mapping Tool maps specific controls to specific techniques — it answers "which controls cover which threats, and where exactly are the gaps?" They're complementary: run the Calculator first to get your overall score, then use the Mapping Tool to understand exactly which controls are responsible for which coverage and where to focus next.

Related Resources