CIS Controls CIS-16.3

Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1212 Exploitation for Credential Access
Comments
Application developers can use root-cause analysis to identify and remediate recurring authentication-validation weaknesses, such as missing replay protections, weak session controls, or flawed request validation. This reduces opportunities for adversaries to replay authentication messages, impersonate authorized parties, and conduct exploitation for credential access.
References
    CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1195.001 Compromise Software Dependencies and Development Tools
    Comments
    Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply-chain compromise through vulnerable or malicious software dependencies and development tools.
    References
      CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1195 Supply Chain Compromise
      Comments
      Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply chain compromise through vulnerable or malicious software dependencies and development tools.
      References
        CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1078 Valid Accounts
        Comments
        Application developers can use root cause analysis to address code or build process practices that expose credentials to ensure that applications do not store sensitive data or credentials insecurely.
        References