Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1535 | Unused/Unsupported Cloud Regions |
Comments
Apply cloud configuration baselines that deactivate unused regions to reduce unmanaged cloud attack surface and help prevent adversaries from creating cloud instances in unused geographic service regions in order to evade detection.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Apply cloud service configuration templates that restrict or disable external data sharing and limit sharing to authorized users or domains to help prevent adversaries from exfiltrating data by transferring the data.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1666 | Modify Cloud Resource Hierarchy |
Comments
Use standard cloud hardening templates to block unauthorized subscription transfers in Azure and prevent use of the AWS LeaveOrganization API through Service Control Policies to help prevent adversaries from modifying hierarchical structures in infrastructure-as-a-service (IaaS) environments.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1689 | Downgrade Attack |
Comments
Apply hardened web server templates that implement policies on internal web servers, such HTTP Strict Transport Security, that enforce the use of HTTPS/network traffic encryption to prevent insecure connections.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1677 | Poisoned Pipeline Execution |
Comments
Use standard hardening templates for continuous integration / continuous development (CI/CD) infrastructure that block unreviewed code execution, isolate untrusted builds, restrict secret access, and prohibit unsafe pipeline triggers to help prevent adversaries from manipulating CI/CD processes.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1685 | Disable or Modify Tools |
Comments
Apply controlled baseline configurations and change management for security-related forwarding mechanisms and firewall rules to help prevent disabling, degrading, or tampering with security tools or applications.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1590.002 | DNS |
Comments
Use standard hardening templates for DNS servers to implement zone transfer policies that permit zone transfers only to validated servers to help prevent adversaries from gathering DNS information.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1213 | Data from Information Repositories |
Comments
Apply standard, industry-recommended hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1213.006 | Databases |
Comments
Apply standard, industry-recommended databases hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1213.004 | Customer Relationship Management Software |
Comments
Apply standard, industry-recommended customer relationship management software hardening templates that enforce data retention, archival, and deletion settings to limit accessible data.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1543 | Create or Modify System Process |
Comments
Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1602 | Data from Configuration Repository | |
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Use standard hardening templates to allowlist MIB objects, implement SNMP views, and disable Smart Install when it is not used, reducing exposure of network-device configuration data.
References
|
| CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | mitigates | T1543.005 | Container Service |
Comments
Using standard, industry-recommended hardening templates for cloud containers to enforce the use of container services in rootless mode can help mitigate the effects of adversaries creating or modifying system-level processes.
References
|