CIS Controls CIS-13.5

Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.5 Manage Access Control for Remote Access mitigates T1021.004 SSH
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110 Brute Force
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.001 Password Guessing
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.003 Password Spraying
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.004 Credential Stuffing
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1621 Multi-Factor Authentication Request Generation
Comments
Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078 Valid Accounts
Comments
Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.004 Cloud Accounts
Comments
Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.002 Domain Accounts
Comments
Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.003 Local Accounts
Comments
Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1133 External Remote Services
Comments
Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021 Remote Services
Comments
Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021.001 Remote Desktop Protocol
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1550 Use Alternate Authentication Material
Comments
Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1550.001 Application Access Token
Comments
Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.
References