MITRE ATT&CK
MITRE ATT&CK is not a compliance framework. It is a knowledge base of how attackers behave in the real world. Controlio uses it as a threat-mapping layer and shows which attack technique a configuration weakness opens the door to.
Why it helps
Compliance frameworks answer which control is missing. ATT&CK answers what that gap makes possible. It ties a finding to a concrete attack scenario, which makes the risk easier to see.
How it is shown
Findings are tied to the relevant ATT&CK techniques, and that mapping appears in the reports as a layer. Next to a finding's technical explanation, you see which attack the defense is meant for.
A layer, not a framework
ATT&CK is not part of the framework compliance scores. It adds threat context on top of them.