CIS Controls CIS-2.3

Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-2.3 Address Unauthorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.011 Lua
Comments
Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.006 Python
Comments
Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.
References
CIS-2.3 Address Unauthorized Software mitigates T1021.005 VNC
Comments
Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.
References
CIS-2.3 Address Unauthorized Software mitigates T1547 Boot or Logon Autostart Execution
Comments
If unauthorized startup software is identified and removed, persistence via installed startup components is disrupted.
References
CIS-2.3 Address Unauthorized Software mitigates T1543.003 Windows Service
Comments
Removal of unauthorized service binaries prevents continued execution of adversary-installed services.
References
CIS-2.3 Address Unauthorized Software mitigates T1543 Create or Modify System Process
Comments
Automated detection and removal of unauthorized installed services can directly disrupt adversary-created system services used for persistence. Enforcement reduces persistence reliability.
References