CIS Controls CIS-11.3

Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-11.3 Protect Recovery Data mitigates T1530 Data from Cloud Storage
Comments
Adversaries collect data directly from improperly secured or compromised cloud storage. When backup or recovery data is stored in cloud object storage, this safeguard requires that recovery data be protected with controls such as encryption and separation, directly reducing unauthorized access to those backup objects
References
CIS-11.3 Protect Recovery Data mitigates T1003.003 NTDS
Comments
Adversaries may obtain NTDS.dit from Domain Controller backups rather than directly from a live Domain Controller and extract credential material from the database. This safeguard requires recovery data to receive equivalent protections, including encryption or separation, which directly restricts unauthorized access to Domain Controller backup copies containing NTDS data
References
CIS-11.3 Protect Recovery Data mitigates T1561.002 Disk Structure Wipe
Comments
Adversaries destroy file-system or partition structures to make data inaccessible. Recovery copies protected independently from the affected storage remain usable, directly enabling restoration despite destruction of the disk structure.
References
CIS-11.3 Protect Recovery Data mitigates T1561.001 Disk Content Wipe
Comments
Adversaries overwrite disk contents to eliminate stored information. Protected recovery copies remain unavailable to the local wiping operation, directly preserving recoverable versions of the destroyed data.
References
CIS-11.3 Protect Recovery Data mitigates T1561 Disk Wipe
Comments
Adversaries wipe disks to destroy data or render systems unusable. Recovery data protected on separate storage remains outside the affected disk's destructive operation, directly preserving the data required to rebuild the system.
References
CIS-11.3 Protect Recovery Data mitigates T1491.002 External Defacement
Comments
Adversaries modify externally visible content. Protected recovery copies preserve the legitimate content and enable replacement of the defaced version, directly reducing the duration and effectiveness of the attack
References
CIS-11.3 Protect Recovery Data mitigates T1491.001 Internal Defacement
Comments
Adversaries alter internally used content or systems. Protected backup copies maintain a trusted version outside the attacker's ordinary modification path, directly enabling restoration of internally defaced data
References
CIS-11.3 Protect Recovery Data mitigates T1491 Defacement
Comments
Adversaries alter content to disrupt operations or damage integrity. Protected recovery copies preserve trusted versions that remain available for restoration, directly limiting the persistence of the defacement.
References
CIS-11.3 Protect Recovery Data mitigates T1486 Data Encrypted for Impact
Comments
Encryption for impact depends on write access to the data the attacker wants to render unusable. Where recovery repositories are immutable, write-protected, or administered through separate credentials, ransomware cannot encrypt or overwrite the protected recovery copy.
References
CIS-11.3 Protect Recovery Data mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
Adversaries manipulate cloud lifecycle policies or similar automation to cause stored data to be deleted. Immutable/versioned recovery storage and restricted lifecycle-policy modification preserve prior backup objects, directly preventing automated deletion from eliminating the recovery copy.
References
CIS-11.3 Protect Recovery Data mitigates T1485 Data Destruction
Comments
Data destruction depends on the attacker being able to delete or overwrite stored data. Where recovery data is held on immutable storage, deletion-protected repositories, or tightly restricted backup systems, those controls can prevent destruction of the protected copy.
References
CIS-11.3 Protect Recovery Data mitigates T1565.001 Stored Data Manipulation
Comments
Stored data manipulation changes data at rest so the altered state is trusted or used operationally. Where recovery repositories enforce immutability, integrity validation, or write restrictions, unauthorized changes to the recovery copy can be blocked or detected.
References
CIS-11.3 Protect Recovery Data mitigates T1565 Data Manipulation
Comments
Adversaries alter enterprise data to affect operations or hide activity. Integrity controls, access restrictions, and protected recovery copies preserve trusted versions that cannot be modified through ordinary production access, directly reducing the lasting effect of manipulation.
References
CIS-11.3 Protect Recovery Data mitigates T1490 Inhibit System Recovery
Comments
Recovery inhibition commonly relies on deleting, modifying, or disabling backup and recovery resources. Where recovery data is protected with immutability, write restrictions, separate credentials, or access isolation, those controls can prevent the compromised access path from removing or altering the recovery copy.
References