STACK LAB

Which security capabilities matter for this threat?

Pick a threat, then build a capability stack. The ledger shows how the stack changes operating burden across the six CSF functions: steps absorbed, handoffs removed, detection stage shift, posture balance. Structural and ordinal claims only.

01Threat

Which threat are you defending against?

1 of 21 selected
Selected scenario
GTG-1002
A4 · 32-step baseline
02Stack

Which capabilities are you evaluating?

3 of 9 selected
Example stack · edit to match yoursTop 3 by steps affected
CSF Function Ledger
Distinct steps affected: 4 · Effect rows: 4 · Catalog 2 · Standards 2 · Mechanism-only 0
MANUAL STEPACCELERATEDABSORBEDCATALOGSTANDARDMECHANISMCLICK A PILLAR FOR STEP DETAIL
Second perspective

Capability impact matrix

Every position is counted from this threat's own ledger: across is how many distinct steps a capability affects, up is how many of those it takes off a human entirely. The dividing lines sit at the midpoint of this threat's range, so they move with the threat and are not a standard.

Steps taken off a human
Strong fit, removes workWeak fit, removes workStrong fit, hands-onWeak fit, hands-on XDR CTEM / Exposure Mgmt AI / MCP Gateway AIDR Agent Identity / NHI AI SOC Assistant Deepfake Detection SASE / SSE CSMA / Mesh Architecture
Distinct steps affected
0 4
In your stackAvailable capabilityNO EFFECT FOR THIS THREAT
Third perspective

What the catalog cannot reach

This section ignores your stack. It asks what every capability category in the catalog could do for this threat if you owned all of them, which is a property of the catalog rather than of a selection, so it does not change as you toggle.

30 of 32 steps stay human whatever you buy.

Of the 32: 2 could be taken off a human by some category, 2 could only ever be accelerated so a person still acts, and 28 are untouched by anything in the catalog.

Govern
nothing reaches it
Identify
1 absorbable, 0 assist only, 4 unreachable
Protect
nothing reaches it
Detect
1 absorbable, 1 assist only, 4 unreachable
Respond
0 absorbable, 1 assist only, 5 unreachable
Recover
nothing reaches it
AbsorbableAssist onlyUnreachable
Untouched by anything in the catalog
Govern 01 Register AI-orchestrated intrusion and AI-system compromise as named enterprise risks (NIST AI RMF Govern)
Govern 02 Set autonomy limits and decision rights across the six domains (IMDA MGF v1.5 dim 1)
Govern 03 Publish NIST AI RMF plus IR 8596 crosswalk (IR 8596 is Initial Preliminary Draft, flag as draft-dependent)
Govern 04 Require AI use-case intake to cite AI 600-1 risks and Manage actions

The floor is the base of a business case, not a verdict on importance. A step no capability can take off a human is not a low-value step; it is a step you will always staff.