CIS Controls CIS-16.7

Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1535 Unused/Unsupported Cloud Regions
Comments
Apply cloud configuration baselines that deactivate unused regions to reduce unmanaged cloud attack surface and help prevent adversaries from creating cloud instances in unused geographic service regions in order to evade detection.
References
    CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1537 Transfer Data to Cloud Account
    Comments
    Apply cloud service configuration templates that restrict or disable external data sharing and limit sharing to authorized users or domains to help prevent adversaries from exfiltrating data by transferring the data.
    References
      CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1666 Modify Cloud Resource Hierarchy
      Comments
      Use standard cloud hardening templates to block unauthorized subscription transfers in Azure and prevent use of the AWS LeaveOrganization API through Service Control Policies to help prevent adversaries from modifying hierarchical structures in infrastructure-as-a-service (IaaS) environments.
      References
        CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1689 Downgrade Attack
        Comments
        Apply hardened web server templates that implement policies on internal web servers, such HTTP Strict Transport Security, that enforce the use of HTTPS/network traffic encryption to prevent insecure connections.
        References
          CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1677 Poisoned Pipeline Execution
          Comments
          Use standard hardening templates for continuous integration / continuous development (CI/CD) infrastructure that block unreviewed code execution, isolate untrusted builds, restrict secret access, and prohibit unsafe pipeline triggers to help prevent adversaries from manipulating CI/CD processes.
          References
            CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1685 Disable or Modify Tools
            Comments
            Apply controlled baseline configurations and change management for security-related forwarding mechanisms and firewall rules to help prevent disabling, degrading, or tampering with security tools or applications.
            References
              CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1590.002 DNS
              Comments
              Use standard hardening templates for DNS servers to implement zone transfer policies that permit zone transfers only to validated servers to help prevent adversaries from gathering DNS information.
              References
                CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213 Data from Information Repositories
                Comments
                Apply standard, industry-recommended hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
                References
                  CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213.006 Databases
                  Comments
                  Apply standard, industry-recommended databases hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
                  References
                    CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213.004 Customer Relationship Management Software
                    Comments
                    Apply standard, industry-recommended customer relationship management software hardening templates that enforce data retention, archival, and deletion settings to limit accessible data.
                    References
                      CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602.001 SNMP (MIB Dump)
                      Comments
                      Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
                      References
                        CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1543 Create or Modify System Process
                        Comments
                        Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
                        References
                          CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602 Data from Configuration Repository
                          CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602.002 Network Device Configuration Dump
                          Comments
                          Use standard hardening templates to allowlist MIB objects, implement SNMP views, and disable Smart Install when it is not used, reducing exposure of network-device configuration data.
                          References
                            CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1543.005 Container Service
                            Comments
                            Using standard, industry-recommended hardening templates for cloud containers to enforce the use of container services in rootless mode can help mitigate the effects of adversaries creating or modifying system-level processes.
                            References