CIS Controls CIS-3.11

Encrypt sensitive data at rest on servers, applications, and databases. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565.001 Stored Data Manipulation
Comments
Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565 Data Manipulation
Comments
Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1003 OS Credential Dumping
Comments
Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1552.004 Private Keys
Comments
Private keys are frequently stored on disk. Encrypting storage can reduce exposure from theft of key files, especially during offline access or storage compromise.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1649 Steal or Forge Authentication Certificates
Comments
Certificates and private keys are commonly stored on disk. Encryption at rest can reduce exposure when attackers attempt to steal certificate material from storage.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1119 Automated Collection
Comments
Adversaries use automated methods to search for and copy data across systems, cloud APIs, pipelines, or RAT functionality. Encryption at rest can mitigate the automated collection of files/storage objects from being usable when the adversary lacks access to the decryption key.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1003.003 NTDS
Comments
NTDS dumping targets Active Directory credential material. Encryption and secure storage of DC backups can prevent an adversary who obtains an offline backup from directly accessing NTDS credential material.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1550.001 Application Access Token
Comments
Application access tokens are sensitive credential material commonly stored in databases, configuration stores, browser profiles, caches, or application files. Encrypting those tokens at rest can prevent an adversary who obtains raw storage, a database backup, snapshot, or filesystem access from reading and reusing the tokens.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1552 Unsecured Credentials
Comments
Credentials and authentication material are often stored within files, databases, configuration repositories, and application data stores. Encrypting sensitive data at rest reduces the usefulness of credential artifacts obtained from protected storage locations by preventing direct access to plaintext credential material.
References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1039 Data from Network Shared Drive
    Comments
    Encryption protects sensitive shared-drive data against unauthorized disclosure
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1530 Data from Cloud Storage
    Comments
    Cloud storage encryption directly protects sensitive stored cloud data.
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1213 Data from Information Repositories
    Comments
    Repository encryption protects stored sensitive data even after unauthorized access.
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1005 Data from Local System
    Comments
    Encryption at rest directly reduces usability of stolen or accessed local data.
    References