Encrypt sensitive data at rest on servers, applications, and databases. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1565 | Data Manipulation |
Comments
Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1003 | OS Credential Dumping |
Comments
Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1552.004 | Private Keys |
Comments
Private keys are frequently stored on disk. Encrypting storage can reduce exposure from theft of key files, especially during offline access or storage compromise.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1649 | Steal or Forge Authentication Certificates |
Comments
Certificates and private keys are commonly stored on disk. Encryption at rest can reduce exposure when attackers attempt to steal certificate material from storage.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1119 | Automated Collection |
Comments
Adversaries use automated methods to search for and copy data across systems, cloud APIs, pipelines, or RAT functionality. Encryption at rest can mitigate the automated collection of files/storage objects from being usable when the adversary lacks access to the decryption key.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1003.003 | NTDS |
Comments
NTDS dumping targets Active Directory credential material. Encryption and secure storage of DC backups can prevent an adversary who obtains an offline backup from directly accessing NTDS credential material.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1550.001 | Application Access Token |
Comments
Application access tokens are sensitive credential material commonly stored in databases, configuration stores, browser profiles, caches, or application files. Encrypting those tokens at rest can prevent an adversary who obtains raw storage, a database backup, snapshot, or filesystem access from reading and reusing the tokens.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1552 | Unsecured Credentials |
Comments
Credentials and authentication material are often stored within files, databases, configuration repositories, and application data stores. Encrypting sensitive data at rest reduces the usefulness of credential artifacts obtained from protected storage locations by preventing direct access to plaintext credential material.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1039 | Data from Network Shared Drive |
Comments
Encryption protects sensitive shared-drive data against unauthorized disclosure
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1530 | Data from Cloud Storage |
Comments
Cloud storage encryption directly protects sensitive stored cloud data.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1213 | Data from Information Repositories |
Comments
Repository encryption protects stored sensitive data even after unauthorized access.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1005 | Data from Local System |
Comments
Encryption at rest directly reduces usability of stolen or accessed local data.
References
|