Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-16.3 | Perform Root Cause Analysis on Security Vulnerabilities | mitigates | T1212 | Exploitation for Credential Access |
Comments
Application developers can use root-cause analysis to identify and remediate recurring authentication-validation weaknesses, such as missing replay protections, weak session controls, or flawed request validation. This reduces opportunities for adversaries to replay authentication messages, impersonate authorized parties, and conduct exploitation for credential access.
References
|
| CIS-16.3 | Perform Root Cause Analysis on Security Vulnerabilities | mitigates | T1195.001 | Compromise Software Dependencies and Development Tools |
Comments
Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply-chain compromise through vulnerable or malicious software dependencies and development tools.
References
|
| CIS-16.3 | Perform Root Cause Analysis on Security Vulnerabilities | mitigates | T1195 | Supply Chain Compromise |
Comments
Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply chain compromise through vulnerable or malicious software dependencies and development tools.
References
|
| CIS-16.3 | Perform Root Cause Analysis on Security Vulnerabilities | mitigates | T1078 | Valid Accounts |
Comments
Application developers can use root cause analysis to address code or build process practices that expose credentials to ensure that applications do not store sensitive data or credentials insecurely.
References
|