CIS Controls CIS-3.3

Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-3.3 Configure Data Access Control Lists mitigates T1078 Valid Accounts
Comments
ACLs constrain which accounts can reach data and therefore directly reduce abuse of valid accounts and local data access for collection.
References
CIS-3.3 Configure Data Access Control Lists mitigates T1005 Data from Local System
Comments
The control either restricts, detects, hardens against, or increases visibility into the adversary behavior associated with this technique. The control reduces unauthorized access opportunities and raises the difficulty of account misuse.
References