CIS Controls CIS-16.8

Maintain separate environments for production and non-production systems.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-16.8 Separate Production and Non-Production Systems mitigates T1098 Account Manipulation
Comments
Separating production and non-production environments with enforced network and administrative boundaries can restrict non-production systems and management paths from reaching production identity infrastructure, reducing opportunities to modify production accounts or authentication settings.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1098.001 Additional Cloud Credentials
Comments
Separate production cloud environments, VPCs, and control-plane access paths can prevent non-production systems or administrators from reaching production identity interfaces used to add cloud credentials to existing accounts.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1557 Adversary-in-the-Middle
Comments
Network separation between production and non-production environments limits the infrastructure and traffic paths visible from either environment, reducing the scope in which an adversary can position for interception or manipulation of communications.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Separating production and non-production broadcast, name-resolution, and SMB communication paths can constrain poisoning activity and prevent non-production systems from directly relaying authentication to production services.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1612 Build Image on Host
Comments
Production and non-production container or virtualization infrastructure can be placed behind separate gateways, firewalls, or control-plane boundaries so a compromised non-production system cannot directly reach production hosts used to build images.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1613 Container and Resource Discovery
Comments
Separating production and non-production container control planes and network paths can prevent a compromised non-production workload from directly querying production container APIs, dashboards, nodes, or resource inventories.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1136 Create Account
Comments
Enforced separation can restrict access from non-production systems and administrative paths to production account-management infrastructure, reducing the ability to create accounts in the production environment from a compromised non-production environment.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1136.002 Domain Account
Comments
Production domain controllers and account-management services can be isolated from non-production networks so non-production systems cannot directly reach the services used to create or manage production domain accounts.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1136.003 Cloud Account
Comments
Separate production cloud environments and restricted control-plane connectivity can limit non-production access to production identity services used to create cloud accounts.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1602 Data from Configuration Repository
Comments
Production configuration-management interfaces and repositories can be placed on network or management segments that are not directly reachable from non-production systems, reducing unauthorized collection of production configuration data.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1602.001 SNMP (MIB Dump)
Comments
Separating production management traffic from non-production networks can restrict SNMP access to approved production management systems and prevent non-production hosts from directly querying production MIB data.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1602.002 Network Device Configuration Dump
Comments
Production network-device management interfaces can be isolated from non-production environments so non-production systems cannot directly access SNMP, Smart Install, or other interfaces used to retrieve production device configurations.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1565 Data Manipulation
Comments
Separating production from non-production systems reduces unauthorized cross-environment access to production data and business processes, limiting the ability of a compromise in development or test infrastructure to directly manipulate production information.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1565.003 Runtime Data Manipulation
Comments
Enforced production boundaries can prevent non-production systems from directly reaching production applications and runtime services, reducing opportunities to alter data while it is being processed in the production environment.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1610 Deploy Container
Comments
Separate production and non-production container control planes can prevent compromised non-production systems from directly accessing production APIs or orchestrators used to deploy containers.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1482 Domain Trust Discovery
Comments
Separating sensitive production identity infrastructure from non-production networks can restrict the connectivity required for systems in non-production environments to enumerate production domains and trust relationships.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Firewalls and access controls between production and non-production environments can permit only required protocols and destinations, blocking unauthorized alternate-protocol transfers across the production boundary.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Production/non-production boundary controls can deny unapproved encrypted protocols, ports, and destinations, limiting exfiltration over symmetrically encrypted non-command-and-control channels across environments.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Production/non-production boundary controls can restrict unapproved encrypted protocols and destinations, limiting exfiltration over asymmetrically encrypted non-command-and-control channels across environments.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Production/non-production segmentation can block unnecessary plaintext protocols and destinations across the environment boundary, directly restricting unencrypted non-command-and-control exfiltration paths.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1190 Exploit Public-Facing Application
Comments
Production services can be placed on separate hosting or security zones from non-production systems so exploitation of an exposed application does not provide unrestricted network reachability into other production resources.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1210 Exploitation of Remote Services
Comments
Separating production and non-production systems with controlled network paths reduces the remote services reachable across environments and limits exploitation-based movement from a compromised non-production system into production.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1133 External Remote Services
Comments
Production remote-access services can be exposed only through dedicated gateways, proxies, or approved access paths that are separate from non-production access, preventing direct remote connectivity from less-trusted environments into production.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1046 Network Service Discovery
Comments
Network segmentation between production and non-production systems limits host and service reachability, reducing the production systems that can be discovered from a compromised development or test environment.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1040 Network Sniffing
Comments
Separating production and non-production network segments limits the traffic, broadcasts, and multicast communications visible from either environment, reducing opportunities to capture production traffic from non-production systems.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1095 Non-Application Layer Protocol
Comments
Production/non-production firewalls and gateways can restrict communication to approved interfaces and protocols, blocking unauthorized non-application-layer traffic across the environment boundary.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1571 Non-Standard Port
Comments
Boundary firewalls between production and non-production environments can allow only explicitly required ports, preventing arbitrary cross-environment communication over non-standard or unauthorized ports.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1563 Remote Service Session Hijacking
Comments
Restricting remote-service traffic between production and non-production security zones reduces the ability of an adversary in one environment to reach and hijack remote sessions in the other.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1563.002 RDP Hijacking
Comments
Blocking unnecessary RDP traffic between production and non-production environments prevents non-production systems from directly reaching production RDP sessions that could otherwise be hijacked.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1021.001 Remote Desktop Protocol
Comments
Production/non-production segmentation can restrict RDP to explicitly approved administrative paths and block ordinary cross-environment RDP connectivity.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1021.003 Distributed Component Object Model
Comments
Firewall rules between production and non-production environments can restrict DCOM and RPC connectivity, reducing opportunities for remote DCOM execution across the environment boundary.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1021.006 Windows Remote Management
Comments
Production systems can use separate WinRM management paths and firewall rules that permit access only from approved administrative systems, preventing general non-production systems from reaching production WinRM services.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1489 Service Stop
Comments
Separating production systems and supporting security or response infrastructure from non-production networks can reduce the ability of an adversary who compromises non-production systems to reach and stop critical production or defensive services.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1072 Software Deployment Tools
Comments
Production deployment and management infrastructure can be isolated from non-production systems and reachable only through approved administrative paths, reducing the ability to abuse a compromised non-production deployment tool to execute software in production.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1199 Trusted Relationship
Comments
Separating production and non-production environments prevents a trusted integration or relationship available in a less-restricted non-production environment from automatically providing equivalent network reachability into production.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1552.007 Container API
Comments
Production container APIs can be isolated behind separate gateways, firewalls, or control-plane networks so non-production workloads cannot directly access production container interfaces that may expose credentials or sensitive configuration.
References
CIS-16.8 Separate Production and Non-Production Systems mitigates T1669 Wi-Fi Networks
Comments
Where non-production or general wireless access is separated from production network segments, enforced segmentation prevents systems that gain Wi-Fi connectivity from directly reaching sensitive production resources.
References