Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.3 | Configure Data Access Control Lists | mitigates | T1078 | Valid Accounts |
Comments
ACLs constrain which accounts can reach data and therefore directly reduce abuse of valid accounts and local data access for collection.
References
|
| CIS-3.3 | Configure Data Access Control Lists | mitigates | T1005 | Data from Local System |
Comments
The control either restricts, detects, hardens against, or increases visibility into the adversary behavior associated with this technique. The control reduces unauthorized access opportunities and raises the difficulty of account misuse.
References
|