CIS Controls CIS-18.3

Remediate penetration test findings based on the enterprise’s documented vulnerability remediation process. This should include determining a timeline and level of effort based on the impact and prioritization of each identified finding.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-18.3 Remediate Penetration Test Findings mitigates T1550.004 Web Session Cookie
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation configures applications and browsers to reduce persistent sessions, shorten cookie validity, require reauthentication, and invalidate session material more aggressively.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1543 Create or Modify System Process
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation restricts insecure service/process behavior.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1606 Forge Web Credentials
Comments
Application and browser configuration can reduce persistent or weakly protected web credential artifacts such as cookies that were found/forged during penetration testing.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1543.005 Container Service
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation is related to configuring container services to run rootless or otherwise reduce unnecessary service privileges, directly constraining persistence or privilege abuse through the container service. The mapping does not apply when the finding requires patching or architectural changes rather than configuration correction.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1555.005 Password Managers
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation deals with enforcing password-manager locking, timeout, vault-access, and related security settings that reduce exposure of stored or decrypted credentials.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1685 Disable or Modify Tools
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation relates to hardening security, logging, and monitoring tools so they are harder to disable or reconfigure, including by enforcing permissions, persistence settings, and service configuration.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1667 Email Bombing
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail service configuration, sender authentication policy, filtering, throttling, and related controls that reduce abusive high-volume email delivery.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1546.013 PowerShell Profile
Comments
This relationship applies when penetration testing identifies the described software-configuration weakness and remediation of the finding removes unnecessary PowerShell profiles, restrict profile modification, or configure PowerShell execution so untrusted profile content is not loaded.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1606.001 Web Cookies
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the applications and browsers to minimize persistent cookies, shorten cookie lifetime, and apply secure cookie settings that reduce reusable credential material.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1590.002 DNS
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the DNS zone transfers to explicitly authorized servers and correct other DNS service settings that expose internal naming information.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1559.002 Dynamic Data Exchange
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding restricts the unnecessary DDE and embedded-content functionality in affected applications, directly reducing an execution path that relies on permissive application configuration.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1566.001 Spearphishing Attachment
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthen mail system sender-authentication, attachment-handling, and filtering policies that reduce delivery of malicious attachments.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1566.002 Spearphishing Link
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail authentication, URL-handling, and browser or mail-client policy to reduce delivery or successful use of malicious links.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1598.002 Spearphishing Attachment
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens sender-authentication and attachment-filtering configuration to reduce spoofed or malicious messages used to solicit sensitive information.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1677 Poisoned Pipeline Execution
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding hardens CI/CD pipeline settings by restricting unreviewed code execution, isolating runners, reducing secrets exposure, constraining triggers, and preventing user-controlled input from being implicitly trusted.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1688 Safe Mode Boot
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding configure system settings so defensive services remain active or recover correctly when Windows is booted into Safe Mode.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1684.002 Email Spoofing
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes and enforces SPF, DKIM, DMARC, and related mail-domain protections to reduce successful sender impersonation.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1539 Steal Web Session Cookie
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes by configuring secure cookie attributes, shorter lifetimes, session invalidation, and reduced persistence in affected applications or browsers.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1537 Transfer Data to Cloud Account
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the cloud applications and services to restrict external sharing, cross account transfers, and unapproved destinations, directly constraining data movement to adversary controlled cloud accounts.
References
CIS-18.3 Remediate Penetration Test Findings mitigates T1535 Unused/Unsupported Cloud Regions
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes disables or restricts unused cloud regions and services so adversaries cannot create or operate resources in locations outside the organization's intended monitoring and governance scope.
References