Catalogue de règles ThreatClaw · source ENISA TIG Mapping Table v1.2 (CC BY 4.0) · généré 2026-01-01
| # | Exigence | Statut | Evidence (par pack, typée) | CSF 2.0 |
|---|---|---|---|---|
| 1.1 | Policy on the security of network and information systems | Couvert | 2 policy clause-précise (CSF/ISO) | PR.AT-02 GV.PO-01 GV.PO-02 GV.OC-03 GV.RM-03 |
| 1.2 | Roles, responsibilities and authorities | Couvert | 2 policy clause-précise (CSF/ISO) | GV.RR-02 GV.SC-02 PR.AT-02 ID.IM-01 ID.IM-02 |
| 2.1 | Risk management framework | Couvert | 1 policy clause-précise (CSF/ISO) | ID.RA-01 ID.RA-02 ID.RA-03 ID.RA-04 ID.RA-05 |
| 2.2 | Compliance monitoring | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | GV.OV-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 2.3 | Independent review of information and network security | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | GV.OV-02 ID.IM-01 |
| 3.1 | Incident handling policy | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | GV.SC-08 RS.MA-01 RS.MA-05 RS.MI-01 RS.MI-02 |
| 3.2 | Monitoring and logging | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | RS.AN-06 RS.AN-07 ID.IM-01 ID.IM-02 ID.IM-03 |
| 3.3 | Event reporting | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | RS.MI-01 RS.CO-02 |
| 3.4 | Event assessment and classification | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.AE-04) | DE.AE-04 RS.MA-02 RS.MA-03 RS.MA-04 ID.IM-01 |
| 3.5 | Incident response | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | RS.MA-01 RS.MA-02 RS.MA-03 RS.MA-04 ID.IM-02 |
| 3.6 | Post-incident reviews | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.IM-01 ID.IM-04 RS.AN-08 |
| 4.1 | Business continuity and disaster recovery plan | Couvert | 1 policy clause-précise (CSF/ISO) | ID.IM-02 ID.IM-03 ID.IM-04 GV.OC-04 GV.SC-08 |
| 4.2 | Backup management | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.DS-11 RC.RP-01 RC.RP-02 ID.IM-03 |
| 4.3 | Crisis management | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.AE-02 DE.AE-03 DE.AE-04 DE.AE-06 DE.AE-07 DE.AE-08 DE.CM-01) | RS.CO-02 RS.CO-03. PR.IR-03 DE.CM-01 ID.AM-03 DE.AE-02 |
| 5.1 | Supply chain security policy | Couvert | 1 policy clause-précise (CSF/ISO) | GV.OC-03 GV.OC-05 GV.SC-01 GV.SC-04 GV.SC-06 |
| 5.2 | Directory of suppliers and service providers | Couvert | 1 policy clause-précise (CSF/ISO) | GV.OC-05 GV.SC-04 ID.IM-01 ID.IM-02 ID.IM-03 |
| 6.1 | Security in acquisition of ICT services, ICT systems or ICT products | Couvert | 1 policy clause-précise (CSF/ISO) | GV.PO-02 GV.SC-06 ID.RA-09 ID.RA-10 ID.IM-01 |
| 6.2 | Secure development life cycle | Couvert | 85 règles SAST maison (7 catégories OWASP, 34 CWE) | ID.AM-08 PR.PS-06 ID.IM-01 ID.IM-02 ID.IM-03 |
| 6.3 | Configuration management | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.PS-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 6.4 | Change management, repairs and maintenance | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.RA-07 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 6.5 | Security testing | Couvert | 85 règles SAST maison (7 catégories OWASP, 34 CWE) | ID.RA-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 6.6 | Security patch management | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.CM-09) | PR.PS-02 DE.CM-09 ID.IM-01 ID.IM-02 ID.IM-03 |
| 6.7 | Network security | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.CM-01) | DE.CM-01 PR.IR-01 PR.PS-05 ID.IM-01 ID.IM-02 |
| 6.8 | Network segmentation | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.IR-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 6.9 | Protection against malicious and unauthorised software | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.CM-01 DE.CM-09) | DE.CM-01 DE.CM-09 PR.PS-05 ID.IM-01 ID.IM-02 |
| 6.10 | Vulnerability handling and disclosure | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.RA-01 ID.RA-02 ID.RA-04 ID.RA-05 ID.RA-06 |
| 7.1 | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | Couvert | 1 policy clause-précise (CSF/ISO) | ID.IM-03 GV.RM-06 ID.IM-01 ID.IM-02 ID.IM-03 |
| 8.1 | Awareness raising and basic cyber hygiene practices | Couvert | 1 policy clause-précise (CSF/ISO) | PR.AT-01 PR.AT-02 ID.IM-01 ID.IM-02 ID.IM-03 |
| 8.2 | Security training | Couvert | 1 policy clause-précise (CSF/ISO) | PR.AT-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 9.1 | Cryptography | Couvert | 1 policy clause-précise (CSF/ISO) | PR.DS-01 PR.DS-02 ID.IM-01 ID.IM-02 ID.IM-03 |
| 10.1 | Human resources security | Couvert | 1 policy clause-précise (CSF/ISO) | PR.AT-02 GV.RR-04 ID.IM-01 ID.IM-02 ID.IM-03 |
| 10.2 | Verification of Background | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | GV.RR-04 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 10.3 | Termination or change of employment procedures | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | GV.RR-04 |
| 10.4 | Disciplinary process | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 11.1 | Access control policy | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.AA-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 11.2 | Management of access rights | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.AA-05 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 11.3 | Privileged accounts and system administration accounts | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 11.4 | Administration systems | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | - |
| 11.5 | Identification | Couvert | 1 policy clause-précise (CSF/ISO) | PR.AA-01 PR.AA-05 PR.AC-02 |
| 11.6 | Authentication | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.AA-05 PR.AA-03 ID.IM-01 ID.IM-02 ID.IM-03 |
| 11.7 | Multi-factor authentication | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.AA-03 |
| 12.1 | Asset classification | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.AM-05 |
| 12.2 | Handling of assets | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.IM-01 |
| 12.3 | Removable media policy | Couvert | 1 policy clause-précise (CSF/ISO) | PR.DS-01 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 12.4 | Asset inventory | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | ID.AM-01 ID.AM-02 ID.AM-03 ID.AM-04 ID.AM-07 |
| 12.5 | Deposit, return or deletion of assets upon termination of employment | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | - |
| 13.1 | Supporting utilities | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.CM-02 DE.CM-06)1 policy clause-précise (CSF/ISO) | DE.CM-02 DE.CM-06 GV.OC-03 GV.OC-05 GV.OC-07 |
| 13.2 | Protection against physical and environmental threats | Cadre (backing) | — backing par cadre (ISO/NIST/CIS) | PR.IR-02 ID.IM-01 ID.IM-02 ID.IM-03 ID.IM-04 |
| 13.3 | Perimeter and physical access control | Couvert | 475 règles / 86 techniques ATT&CK (capacité DETECT DE.CM-02) | PR.AA-06 DE.CM-02 |
Projection via le mapping ReCyF↔NIS2. Couverture de conception transitive.
| Article | Intitulé | Pack | Adossement |
|---|---|---|---|
| art. 8 | detections | Identification des menaces et vulnérabilités (sources de risque) | |
| art. 9 | policy | Protection & prévention (chiffrement, contrôle d'accès, config) — via policy-as-code | |
| art. 10 | detections | Détection prompte d'activités anormales — via règles Sigma/ATT&CK | |
| art. 24 | redteam | Programme de tests de résilience opérationnelle numérique | |
| art. 25 | redteam | Tests des outils et systèmes TIC | |
| art. 26 | redteam | Tests d'intrusion fondés sur la menace (TLPT) — SUPPORT, pas la prestation certifiée | |
| art. 27 | redteam | Exigences des testeurs TLPT — SUPPORT |