Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021.004 | SSH |
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110 | Brute Force |
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.001 | Password Guessing |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.003 | Password Spraying |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.004 | Credential Stuffing |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1621 | Multi-Factor Authentication Request Generation |
Comments
Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078 | Valid Accounts |
Comments
Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.004 | Cloud Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.002 | Domain Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.003 | Local Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1133 | External Remote Services |
Comments
Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021 | Remote Services |
Comments
Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1550 | Use Alternate Authentication Material |
Comments
Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1550.001 | Application Access Token |
Comments
Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.
References
|