Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-11.3 | Protect Recovery Data | mitigates | T1530 | Data from Cloud Storage |
Comments
Adversaries collect data directly from improperly secured or compromised cloud storage. When backup or recovery data is stored in cloud object storage, this safeguard requires that recovery data be protected with controls such as encryption and separation, directly reducing unauthorized access to those backup objects
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1003.003 | NTDS |
Comments
Adversaries may obtain NTDS.dit from Domain Controller backups rather than directly from a live Domain Controller and extract credential material from the database. This safeguard requires recovery data to receive equivalent protections, including encryption or separation, which directly restricts unauthorized access to Domain Controller backup copies containing NTDS data
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1561.002 | Disk Structure Wipe |
Comments
Adversaries destroy file-system or partition structures to make data inaccessible. Recovery copies protected independently from the affected storage remain usable, directly enabling restoration despite destruction of the disk structure.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1561.001 | Disk Content Wipe |
Comments
Adversaries overwrite disk contents to eliminate stored information. Protected recovery copies remain unavailable to the local wiping operation, directly preserving recoverable versions of the destroyed data.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1561 | Disk Wipe |
Comments
Adversaries wipe disks to destroy data or render systems unusable. Recovery data protected on separate storage remains outside the affected disk's destructive operation, directly preserving the data required to rebuild the system.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1491.002 | External Defacement |
Comments
Adversaries modify externally visible content. Protected recovery copies preserve the legitimate content and enable replacement of the defaced version, directly reducing the duration and effectiveness of the attack
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1491.001 | Internal Defacement |
Comments
Adversaries alter internally used content or systems. Protected backup copies maintain a trusted version outside the attacker's ordinary modification path, directly enabling restoration of internally defaced data
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1491 | Defacement |
Comments
Adversaries alter content to disrupt operations or damage integrity. Protected recovery copies preserve trusted versions that remain available for restoration, directly limiting the persistence of the defacement.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1486 | Data Encrypted for Impact |
Comments
Encryption for impact depends on write access to the data the attacker wants to render unusable. Where recovery repositories are immutable, write-protected, or administered through separate credentials, ransomware cannot encrypt or overwrite the protected recovery copy.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1485.001 | Lifecycle-Triggered Deletion |
Comments
Adversaries manipulate cloud lifecycle policies or similar automation to cause stored data to be deleted. Immutable/versioned recovery storage and restricted lifecycle-policy modification preserve prior backup objects, directly preventing automated deletion from eliminating the recovery copy.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1485 | Data Destruction |
Comments
Data destruction depends on the attacker being able to delete or overwrite stored data. Where recovery data is held on immutable storage, deletion-protected repositories, or tightly restricted backup systems, those controls can prevent destruction of the protected copy.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Stored data manipulation changes data at rest so the altered state is trusted or used operationally. Where recovery repositories enforce immutability, integrity validation, or write restrictions, unauthorized changes to the recovery copy can be blocked or detected.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1565 | Data Manipulation |
Comments
Adversaries alter enterprise data to affect operations or hide activity. Integrity controls, access restrictions, and protected recovery copies preserve trusted versions that cannot be modified through ordinary production access, directly reducing the lasting effect of manipulation.
References
|
| CIS-11.3 | Protect Recovery Data | mitigates | T1490 | Inhibit System Recovery |
Comments
Recovery inhibition commonly relies on deleting, modifying, or disabling backup and recovery resources. Where recovery data is protected with immutability, write restrictions, separate credentials, or access isolation, those controls can prevent the compromised access path from removing or altering the recovery copy.
References
|