CIS Controls CIS-16.11

Leverage vetted modules or services for application security components, such as identity management, encryption, auditing, and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern operating systems provide effective mechanisms for identification, authentication, and authorization and make those mechanisms available to applications. Use only standardized, currently accepted, and extensively reviewed encryption algorithms. Operating systems also provide mechanisms to create and maintain secure audit logs.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1574.001 DLL
Comments
Use vetted platform and application security modules to validate component integrity; where applicable, include hash values in manifest files to help prevent malicious DLL side-loading.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1550 Use Alternate Authentication Material
Comments
Using vetted authentication modules or services that support token-binding protections that cryptographically bind a token to a secret can help prevent the token from being used without knowledge of the secret or possession of the device the token is tied to.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1212 Exploitation for Credential Access
Comments
Validating authentication requests using vetted platform authentication and identity management services, rather than relying on custom authentication code, can help prevent adversaries from targeting credentialing and authentication mechanisms for exploitation.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1574 Hijack Execution Flow
Comments
Use vetted platform services and trusted application security modules that validate component integrity; where applicable, include hash values in manifest files to help prevent malicious library side-loading.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1550.001 Application Access Token
Comments
Using vetted authentication modules or services that support token-binding protections that cryptographically bind a token to a secret can help prevent the token from being used without knowledge of the secret or possession of the device the token is tied to.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1195.001 Compromise Software Dependencies and Development Tools
Comments
Application developers should be cautious when selecting third-party libraries to integrate into their application. Additionally, where possible, developers should lock software dependencies to specific versions rather than pulling the latest version on build.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1195 Supply Chain Compromise
Comments
Application developers should be cautious when selecting third-party libraries to integrate into their application. Additionally, where possible, developers should lock software dependencies to specific versions rather than pulling the latest version on build.
References
CIS-16.11 Leverage Vetted Modules or Services for Application Security Components mitigates T1496.003 SMS Pumping
Comments
Using a vetted SMS/messaging service that provides and is configured with anti-abuse controls such as CAPTCHA or equivalent bot protection can help prevent adversaries from leveraging messaging services for SMS pumping.
References