Coverage
What we cover, and what we don’t.
The control areas we track, which of them a Control Pack now covers, and why the rest are still open. This describes the library. It says nothing about your system.
How to read this
A map is not an assessment.
These records say what the library asks about. Lining a pack up against an outside framework is a point of comparison, not a claim that one satisfies the other, and nothing here is a certification or a compliance result.
Control areas
What has a pack, and what doesn’t
Each area below is either covered by a pack you can open and read, or still open with the reason.
Points of comparison
How this lines up with ATT&CK
ATT&CK describes what an attacker does. A pack asks what you decided while building. The two meet in places, and these are the clearest of them — not a full mapping.
Go deeper
Read the packs themselves.
Every pack shows when it applies, what it asks you to decide, the tests it expects, and what it does not claim.