comparative · 5 frameworks × 4 capabilities
Threxen · sector coverage matrix

One control-by-control mapping, across all five frameworks Threxen ships against.

Pick a capability. Read across the five regulator columns. Each cell maps the agent action to the named article, requirement, or control the auditor will be asked to attest to. Click any framework header to sort the rows by its first mapped article.

5 × 4
52 article mappings
sortable · live from /api/sector-coverage
4 capabilities · 5 frameworks · rows sorted by capability (ascending)
live · latest pack
Decoy surface area

High-fidelity decoys — documents, SaaS endpoints, kubeconfigs — are laid on the same telemetry plane as production, so a single verdict can call them by name.

verdict attribution ≤ 1 touch
2 articles
  • §164.308(a)(1)(ii)(A)

    Risk analysis — conduct accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

  • §164.312(e)(1)

    Transmission security — implement security measures to guard against unauthorized access to ePHI in transit; a poisoned decoy channel surfaces the actor before any real data leaves the boundary.

3 articles
  • Req. 6.4

    Public-facing web applications are protected by application-layer controls; the decoy surface is a control surface that learns from touch.

  • Req. 11.4

    Use of techniques to detect and alert on unauthorized wireless encryption protocols and rogue wireless devices.

  • Req. A3.4.1

    Sensitive authentication data (SAD) is not stored after authorization; the decoy fakes SAD that triggers containment rather than authorization.

3 articles
  • SI-4 System monitoring

    Monitor the system to detect attacks, indicators of potential attacks, and unauthorized activity; the decoy surface sits inside continuous monitoring as a runnable workload.

  • RA-3 Risk assessment

    Conduct a risk assessment including likelihood and magnitude of harm; a touch on a decoy is a measurable risk signal.

  • CA-7 Continuous monitoring

    Develop a continuous monitoring strategy and implement continuous monitoring programs; decoys + watchdogs are the ConMon engines.

2 articles
  • Art. 18(1) Resilience testing

    Establish and maintain a digital operational resilience testing programme; decoy surface is a live test under realistic conditions.

  • Art. 5 ICT risk framework

    Maintain an effective and comprehensive ICT risk management framework as part of the overall risk management system; the touch is recorded as a risk signal.

2 articles
  • Art. 21(2)(f) Vulnerability handling

    Procedures for vulnerability handling and disclosure; a touch on a decoy is a vulnerability signal before it surfaces on a real surface.

  • Art. 21(2)(e) Supply chain security

    Supply-chain security including security-related aspects of supplier relationships; decoy surfaces map the lateral pathways the actor explored.

Hash-chained evidence packet

A sealed evidence packet lands on the analyst desk. Actor confidence, toolchain map, and regulatory framing bound to the framework the customer reports under.

replayable without re-running
3 articles
  • §164.308(a)(6)(ii)

    Response and reporting — identify, respond to, and document security incidents; the playbook packet is the reportable record.

  • §164.316(b)(1)

    Documentation retention — maintain written policies/procedures and documentation of actions/activities for six years; the hash chain is the tamper-evident form.

  • §164.312(c)(1)

    Integrity — implement policies and procedures to protect ePHI from improper alteration or destruction; the chain seals the verdict trail end-to-end.

3 articles
  • Req. 10.2

    Audit logs record all required events with required content — actor, timestamp, event type, success/failure, origination, affected component.

  • Req. 12.10

    Document and implement an incident response plan — the playbook packet is the on-call form the analyst attests to.

  • Req. 10.5

    Audit log files are protected from unauthorized modification and retained for at least 12 months with the most recent three months immediately available.

3 articles
  • AU-2 Event logging

    Identify the types of events that the system is capable of logging and select for ongoing collection; the packet is the corpus the AO attests to.

  • AU-9 Protection of audit information

    Protect audit information and audit tools from unauthorized access, modification, and deletion; the hash chain is the tamper-evident form.

  • AU-6 Audit review, analysis, and reporting

    Review and analyze information system audit records for indications of inappropriate or unusual activity; the packet is the analyst deliverable.

3 articles
  • Art. 17 Incident reporting

    Initial, intermediate, and final notifications on major ICT-related incidents and voluntary notification of significant cyber threats.

  • Art. 19 Operational resilience testing outcomes

    Capture findings of digital operational resilience testing and ensure follow-up action; the packet is the capture-of-record.

  • Art. 28 Contractual arrangements

    Contractual terms with ICT third-party service providers must include exit strategies, audit rights, and incident cooperation; the chain is the audit trail.

3 articles
  • Art. 23 Reporting obligations

    Early warning within 24 hours of becoming aware of an incident, incident notification within 72 hours, and final report within one month.

  • Art. 21(2)(b) Incident handling

    Incident handling procedures; the hash-chained packet is the on-call form the analyst attests to.

  • Art. 24 Crisis management

    Member States ensure essential and important entities have designated crisis-management authorities; the packet is the cross-border delegation surface.

Host isolation

Containment revokes credentials, tunnels out suspect interfaces, and quarantines the host in under a second of a confirmed verdict. Every action is reversibly recorded.

mean time-to-contain ≤ 1s
3 articles
  • §164.308(a)(1)(ii)(B)

    Risk management — implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

  • §164.308(a)(6)(i)

    Security incident procedures — identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects.

  • §164.310(c)

    Workstation use — policies and procedures specifying proper functions, manner, and environment for workstation use.

2 articles
  • Req. 1.2

    Network security controls — configure NSCs to restrict untrusted traffic; one-line containment revokes the tunnel interface faster than a NAT change can be made.

  • Req. 11.5

    Use of intrusion-detection and/or intrusion-prevention techniques to detect, alert on, and mitigate unauthorized network activity.

3 articles
  • IR-4 Incident handling

    Implement an incident handling program including preparation, detection, analysis, containment, eradication, and recovery; containment is the muscle.

  • SC-7 Boundary protection

    Monitor and control communications at the external boundary and key internal boundaries; one-click containment moves the host off the boundary.

  • AC-6 Least privilege

    Allow only authorized accesses which are necessary to accomplish assigned organizational tasks; isolation revokes privilege the verifier no longer merits.

2 articles
  • Art. 9(2) Protection

    Continuously monitor and control the security of ICT systems and the underlying infrastructure to preserve the integrity, availability, and confidentiality of data.

  • Art. 12(4) Response

    Recovery procedures and business continuity plans are tested, reviewed, and updated; isolation is the response half of the loop.

2 articles
  • Art. 21(2)(d) Business continuity

    Business continuity and disaster recovery plans, including a crisis management plan; isolation is the operative half of that plan under attack.

  • Art. 21(2)(a) Risk analysis

    Policies on risk analysis and information system security; the containment event is the documented risk signal that policy responds to.

Live credential poisoning

The moment an adversary touches a decoy, the agent fingerprints the tooling and poisons the credentials it would have used — the replay fails at the IdP, not at Threxen.

IdP replay rejection
3 articles
  • §164.308(a)(5)(ii)(D)

    Password management — procedures for creating, changing, and safeguarding passwords; pairs with active poisoning as a defense-in-depth layer at the IdP.

  • §164.312(a)(2)(iii)

    Automatic logoff — terminate an electronic session after a predetermined time of inactivity; poisoning the credential blocks the next session renewal.

  • §164.312(b)

    Audit controls — implement hardware, software, procedural mechanisms to record and examine activity in information systems containing ePHI.

3 articles
  • Req. 8.4

    Multi-factor authentication for all non-console admin access and all access to the cardholder data environment.

  • Req. 8.5

    Authentication credentials are managed to prevent misuse — the poison invalidates captured creds at the IdP rather than at the CDE perimeter.

  • Req. 3.5

    Primary account number (PAN) is unreadable anywhere it is stored — poisoned creds never reach the store.

3 articles
  • IA-2 Identification and authentication

    Uniquely identify and authenticate organizational users; poisoning the captured credential blocks the next session renewal.

  • IA-5 Authenticator management

    Manage authenticators including initial distribution, lost/compromised, and revocation; the poison is the fastest revocation Threxen ships.

  • AC-2 Account management

    Identify and select account types, conditions for group membership, and required attributes; the packet reports what was active when the touch happened.

2 articles
  • Art. 9(4) Identity

    ICT authentication mechanisms are robust, periodically reviewed, and aligned to a strong baseline; the poison invalidates captured creds at the IdP.

  • Art. 25(2) Third-party concentrations

    Identify and document concentration risks arising from ICT third-party providers; if the poisoning was downstream of an ICT provider, the packet names it.

2 articles
  • Art. 21(2)(g) Cryptography

    Use of cryptography and encryption — including per-tenant key envelopes — so a captured credential cannot replay under stolen key material.

  • Art. 21(2)(c) Access control

    Policies on access control and asset management; the poison blocks the credential the actor believed was valid.

↔ horizontally scrollable on narrow viewports · tap a framework header to sort by its first mapped article

Per-framework pillars

Pick a column. Read the pillar essay that drives it.

Each framework pillar essay expands a column of this matrix and walks the analyst through the agent loop pinned to that regulator. Cross-link from any pillar essay back into this matrix via the callout on the essay footer.

All resourcessecurity & compliance posture →Threxen · sector coverage · static matrix · drift-free by construction