# TIBER-EU Framework for Threat Intelligence-Based Ethical Red Teaming

Framework id: `tiber_eu`. Threat-Led Testing. Publisher: European Central Bank (ECB). Version: 2018. Region: EU. Mapping licence: CC BY-SA 4.0.
Source text: https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (10, average coverage 58%)
- TIBER.BT Blue Team Response — Real-time detection assessment, incident response evaluation, and escalation procedures: AU-02, AU-06, AU-12, AU-14, CA-07, IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, PM-14, SI-04 (78%)
- TIBER.CLOSE Closure Phase — 360-degree feedback, red team report, threat intelligence report, and remediation plan: CA-02, CA-05, IR-03, IR-04, IR-05, PM-04, PM-06, PM-14, PM-31 (70%)
- TIBER.CONF Confidentiality and Risk Management — Test risk mitigation, operational safeguards, and data protection: AC-01, AC-03, AC-06, MP-01, MP-06, PE-03, PL-04, PM-09, PM-28, PT-01, PT-03, RA-07, SC-08, SC-28, SI-12 (68%)
- TIBER.GTL Generic Threat Landscape — Sector-wide threat landscape report and macro-level threat assessment: PM-15, PM-16, RA-03, RA-05, SI-05, SR-08 (52%)
- TIBER.PREP Preparation Phase — Scope definition, entity engagement, regulatory coordination, and white team formation: CA-08, PL-01, PL-02, PL-04, PM-01, PM-02, PM-09, PM-14, PM-28, PM-29 (60%)
- TIBER.PROV Provider Requirements — Threat intelligence provider and red team provider qualification standards: SA-04, SA-09, SA-21, SR-01, SR-02, SR-06 (48%)
- TIBER.REM Remediation and Follow-Up — Remediation tracking, control improvement validation, and attestation: CA-02, CA-05, CA-07, PM-04, PM-06, PM-31, RA-07, SI-02 (72%)
- TIBER.RT Red Team Testing — Controlled adversary simulation, multi-phase attack execution, and live production testing: CA-08, PM-14, RA-05, RA-06, RA-10, SC-26, SC-35 (55%)
- TIBER.TTI Targeted Threat Intelligence — Entity-specific threat intelligence, attack scenario development, and flag planting: PM-16, RA-03, RA-05, RA-10, SI-05 (42%)
- TIBER.XB Cross-Border Coordination — Mutual recognition, multi-authority testing, and joint assessments: PM-08, PM-15 (35%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=tiber_eu
- Control-to-clause mappings as JSON: /api/v1/frameworks/tiber_eu?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/tiber-eu.json
- Page for people: /frameworks/tiber-eu/
