Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-11.2 | Perform Automated Backups | mitigates | T1490 | Inhibit System Recovery |
Comments
Adversaries inhibit recovery by deleting or disabling backups, snapshots, recovery catalogs, and related recovery mechanisms. This safeguard requires automated, recurring backups of in-scope enterprise assets, ensuring that recoverable copies are created on a regular basis and thereby reducing the effectiveness of attempts to eliminate available recovery data.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Adversaries alter data stored in files, databases, or other repositories. Automated backups preserve historical versions of the stored data, directly enabling recovery of the unmodified state.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1565 | Data Manipulation |
Comments
Adversaries alter data to affect decisions, processes, or system outcomes. Automated backups preserve earlier trusted versions of that data, directly enabling defenders to replace manipulated information with a known-good state.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1491.002 | External Defacement |
Comments
External defacement changes public-facing website or application content. Where the affected content and configuration are included in automated backups, known-good versions can be restored and the defaced state can be removed.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1491.001 | Internal Defacement |
Comments
Internal defacement modifies organizational web, application, or other internal content. Where that content is included in automated backups, known-good versions can replace the altered resources and shorten the duration of the defacement.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1491 | Defacement |
Comments
Automated backups preserve trusted versions of the modified data or content, directly enabling restoration of the pre-defacement state.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1485.001 | Lifecycle-Triggered Deletion |
Comments
Lifecycle-triggered deletion relies on cloud retention or lifecycle rules deleting stored objects. Where automated backups retain the same data outside the affected lifecycle policy or account, those copies survive the deletion and can be restored.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1561.002 | Disk Structure Wipe |
Comments
Disk structure wiping corrupts partitions, filesystems, or other structures needed to access stored data. Automated backups preserve recoverable copies independent of the damaged disk structure, directly supporting restoration.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1561.001 | Disk Content Wipe |
Comments
Disk content wiping destroys the data stored on an affected device. Automated backups preserve prior copies of the overwritten data, directly enabling restoration.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1561 | Disk Wipe |
Comments
Adversaries erase disk data or structures to render systems unusable. Automated backups preserve data outside the destroyed disk state, directly enabling restoration after the wipe.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1486 | Data Encrypted for Impact |
Comments
Ransomware and similar impact activity encrypt accessible production data to deny legitimate use. Automated backups preserve recoverable copies from before encryption, directly reducing the attacker's ability to make the encrypted data permanently unavailable.
References
|
| CIS-11.2 | Perform Automated Backups | mitigates | T1485 | Data Destruction |
Comments
Adversaries destroy data to impair operations or deny access to information. Automated backups preserve earlier copies of the affected data, directly enabling restoration and reducing the operational effectiveness of the destruction.
References
|