Retain data according to the enterprise’s documented data management process. Data retention must include both minimum and maximum timelines.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.009 | Clear Persistence |
Comments
This sub-technique removes scheduled tasks or registry keys after use. Retaining system modification logs according to enterprise timelines ensures the lifecycle of the persistence mechanism remains fully reviewable.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.008 | Clear Mailbox Data |
Comments
This sub-technique permanently purges emails to hide phishing or exfiltration. CIS 3.4 requires a minimum retention window for email archives, blocking adversaries from destroying corporate messaging records.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.007 | Clear Network Connection History and Configurations |
Comments
This sub-technique wipes local network state data and active connection logs. Enforcing retention timelines on network telemetry ensures lateral movement records survive local configuration resets.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.003 | Clear Command History |
Comments
This sub-technique purges terminal histories like .bash_history or PowerShell logs. Data retention policies mandate logging shell commands directly to a central repository, preserving the operational history despite local terminal purges.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1685.005 | Clear Windows Event Logs |
Comments
This technique targets local Windows security and system event logs. Enforcing a minimum retention timeline ensures Windows event data is moved off-host and preserved, defeating local log-clearing attempts.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1685.006 | Clear Linux or Mac System Logs |
Comments
This technique deletes critical Unix artifacts like /var/log system logs. Documented retention processes guarantee that Unix system trails are streamed to a repository where minimum storage timelines are strictly enforced.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070 | Indicator Removal |
Comments
This overarching technique covers deleting artifacts across an environment. CIS 3.4 protects the evidence chain by establishing mandatory retention periods that an attacker cannot alter or shorten.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1485 | Data Destruction |
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker. Data retention policies protect against adversaries deleting logs by mandating strict storage lifecycles, off-site replication, and immutability.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070 | Indicator Removal |
Comments
Data Retention restricts, hardens against, or increases visibility into the adversary behavior.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1485 | Data Destruction |
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker.
References
|