Implement an automated tool, such as a host-based Data Loss Prevention (DLP) tool to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's data inventory.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions commonly inspect and restrict uploads to external cloud services.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP inspection capabilities may identify sensitive-data transfer across non-standard protocols.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1567 | Exfiltration Over Web Service |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Web upload monitoring and restriction are core DLP use cases.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1052.001 | Exfiltration over USB |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Device-control and removable-media DLP policies directly target USB-based exfiltration.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1041 | Exfiltration Over C2 Channel |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions explicitly monitor and restrict unauthorized outbound transfer of sensitive data.
References
|