CIS Controls CIS-12.8

Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the enterprise's primary network and not be allowed internet access.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1563.002 RDP Hijacking
Comments
Dedicated administrative workstations and segmented management networks reduce who can reach hosts carrying privileged RDP sessions and separate administrative activity from ordinary user networks. This does not prevent hijacking after the admin host itself is compromised, but it directly reduces network exposure of those sessions.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1563 Remote Service Session Hijacking
Comments
Adversaries hijack existing SSH, RDP, or other remote-management sessions. Keeping administrative sessions on dedicated, segmented resources reduces exposure of those sessions to compromised user endpoints and limits unnecessary network paths to privileged remote services.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1557 Adversary-in-the-Middle
Comments
Dedicated administrative resources are explicitly segmented from the primary enterprise network and denied Internet access. That separation reduces opportunities for adversaries on user or Internet-connected networks to position themselves between administrative systems and managed infrastructure, directly shrinking the attack surface for interception of privileged sessions.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1071.001 Web Protocols
Comments
Adversaries use HTTP or HTTPS to communicate with command-and-control infrastructure. Default-deny Internet egress on dedicated administrative resources prevents direct connections to external HTTP/S C2 infrastructure, directly disrupting the communication channel.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1105 Ingress Tool Transfer
Comments
Adversaries transfer tools and payloads onto compromised systems from external infrastructure. Dedicated administrative resources have no direct Internet access and permit file transfer only through controlled internal mechanisms, directly preventing arbitrary external payload retrieval.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1021.006 Windows Remote Management
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Administrative network controls permit WinRM only over approved management paths, directly denying unauthorized WinRM connectivity.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Adversaries use alternate network protocols to transfer data outside the environment. Protocol-aware egress filtering and destination restrictions in the administrative enclave directly block unauthorized alternate-protocol exfiltration channels.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1571 Non-Standard Port
Comments
Adversaries use unexpected ports for command-and-control to evade standard network restrictions. The administrative enclave permits only explicitly approved ports and denies all others, directly preventing outbound communication over unauthorized ports.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1095 Non-Application Layer Protocol
Comments
Adversaries use non-application-layer protocols for command-and-control or data transfer. The administrative enclave enforces default-deny egress with explicit protocol allowlisting, directly blocking unauthorized low-level communications.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1133 External Remote Services
Comments
Adversaries use externally accessible remote services to reach internal or privileged resources. Dedicated administrative systems are not externally reachable and accept access only through controlled administrative paths, directly preventing external remote-service access to the enclave.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1567 Exfiltration Over Web Service
Comments
Adversaries transfer stolen data to external Web services. Dedicated administrative resources have no Internet egress, directly preventing connections to the external Web destinations required by the technique.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1102 Web Service
Comments
Adversaries use external Web services as command-and-control infrastructure. Dedicated administrative systems have no direct Internet access, directly preventing them from establishing command-and-control sessions with external Web services.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Adversaries manipulate local name-resolution traffic and relay authentication to reachable services. Separating administrative systems from general-user broadcast domains and restricting SMB paths directly reduces poisoning opportunities and viable privileged relay targets.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic visible from a compromised privileged system to collect credentials or operational information. Isolating administrative resources from the primary network reduces the traffic and broadcast domains visible to those systems, directly limiting passive collection opportunities.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1046 Network Service Discovery
Comments
Adversaries probe network systems to identify accessible services and hosts. Administrative enclave segmentation restricts network visibility and reachability across the enclave boundary, directly reducing the systems and services available for discovery.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1210 Exploitation of Remote Services
Comments
Adversaries exploit vulnerable remote services on reachable systems to move laterally. Segmentation of administrative resources restricts the remote services reachable into and out of the privileged enclave, directly reducing lateral exploitation opportunities.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1189 Drive-by Compromise
Comments
Adversaries compromise systems when users access malicious or compromised Internet content. Dedicated administrative resources are prohibited from general Internet access, directly removing ordinary Web browsing as an initial-access path to privileged systems.
References