Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1561.002 | Disk Structure Wipe |
Comments
Disk structure wiping damages partitions, filesystems, or boot structures required to access a system. Recovery data stored on an isolated repository remains unaffected by those disk-level changes and can be used to rebuild the system.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1561.001 | Disk Content Wipe |
Comments
Disk content wiping destroys data on the affected storage device. An isolated recovery repository is not dependent on that disk and preserves the data needed to restore the wiped system.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1561 | Disk Wipe |
Comments
Adversaries erase disk data or structures to make systems unusable. Offline, cloud-separated, or off-site recovery copies remain outside the disk-wipe operation, directly preserving data required for restoration.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1491.002 | External Defacement |
Comments
External defacement modifies public-facing web or application content. Where an isolated recovery instance contains the affected content and configuration, known-good copies can be restored and the attacker-controlled state removed.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1491.001 | Internal Defacement |
Comments
Internal defacement changes internal application or web content visible to users. Where an isolated recovery instance preserves known-good versions of that content, the altered files or configuration can be replaced with trusted copies.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1491 | Defacement |
Comments
Adversaries alter operational or visible data to damage integrity. An isolated recovery copy preserves the trusted pre-defacement state, directly enabling restoration.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1490 | Inhibit System Recovery |
Comments
Recovery inhibition relies on eliminating backups, snapshots, or other recovery resources available to the victim. An isolated recovery instance remains outside the compromised recovery path, preventing the attacker from removing every usable recovery copy through the same access.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1486 | Data Encrypted for Impact |
Comments
Encryption for impact depends on the attacker being able to reach and modify usable data. An isolated recovery copy that is inaccessible through the compromised production path remains unencrypted and available for restoration.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1485.001 | Lifecycle-Triggered Deletion |
Comments
Lifecycle-triggered deletion relies on cloud policies automatically removing stored objects. Where the isolated recovery copy resides in a separate account, vault, or lifecycle boundary, those deletion rules do not affect the recovery copy.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1485 | Data Destruction |
Comments
Data destruction removes or overwrites production data to make it unrecoverable. An isolated recovery copy sits outside the same destructive access path, preserving data that can be restored after production copies are destroyed.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Stored data manipulation relies on altered data remaining authoritative or being used by downstream systems. Where the isolated recovery environment retains versioned or known-good data from before the manipulation, the modified production copy can be replaced with a trusted version.
References
|
| CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | mitigates | T1565 | Data Manipulation |
Comments
Adversaries manipulate data to affect operations or hide activity. An isolated recovery copy remains outside the compromised production write path, preserving a trusted version that can replace manipulated data.
References
|