CIS Controls CIS-3.4

Retain data according to the enterprise’s documented data management process. Data retention must include both minimum and maximum timelines.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-3.4 Enforce Data Retention mitigates T1070.009 Clear Persistence
Comments
This sub-technique removes scheduled tasks or registry keys after use. Retaining system modification logs according to enterprise timelines ensures the lifecycle of the persistence mechanism remains fully reviewable.
References
CIS-3.4 Enforce Data Retention mitigates T1070.008 Clear Mailbox Data
Comments
This sub-technique permanently purges emails to hide phishing or exfiltration. CIS 3.4 requires a minimum retention window for email archives, blocking adversaries from destroying corporate messaging records.
References
CIS-3.4 Enforce Data Retention mitigates T1070.007 Clear Network Connection History and Configurations
Comments
This sub-technique wipes local network state data and active connection logs. Enforcing retention timelines on network telemetry ensures lateral movement records survive local configuration resets.
References
CIS-3.4 Enforce Data Retention mitigates T1070.003 Clear Command History
Comments
This sub-technique purges terminal histories like .bash_history or PowerShell logs. Data retention policies mandate logging shell commands directly to a central repository, preserving the operational history despite local terminal purges.
References
CIS-3.4 Enforce Data Retention mitigates T1685.005 Clear Windows Event Logs
Comments
This technique targets local Windows security and system event logs. Enforcing a minimum retention timeline ensures Windows event data is moved off-host and preserved, defeating local log-clearing attempts.
References
CIS-3.4 Enforce Data Retention mitigates T1685.006 Clear Linux or Mac System Logs
Comments
This technique deletes critical Unix artifacts like /var/log system logs. Documented retention processes guarantee that Unix system trails are streamed to a repository where minimum storage timelines are strictly enforced.
References
CIS-3.4 Enforce Data Retention mitigates T1070 Indicator Removal
Comments
This overarching technique covers deleting artifacts across an environment. CIS 3.4 protects the evidence chain by establishing mandatory retention periods that an attacker cannot alter or shorten.
References
CIS-3.4 Enforce Data Retention mitigates T1485 Data Destruction
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker. Data retention policies protect against adversaries deleting logs by mandating strict storage lifecycles, off-site replication, and immutability.
References
CIS-3.4 Enforce Data Retention mitigates T1070 Indicator Removal
Comments
Data Retention restricts, hardens against, or increases visibility into the adversary behavior.
References
CIS-3.4 Enforce Data Retention mitigates T1485 Data Destruction
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker.
References