Securely dispose of data as outlined in the enterprise’s documented data management process. Ensure the disposal process and method are commensurate with the data sensitivity.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1530 | Data from Cloud Storage |
Comments
Secure disposal reduces sensitive data retained in cloud object storage, lowering the value of compromised storage access
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1552 | Unsecured Credentials |
Comments
This applies when secure disposal explicitly removes old credential files, keys, exports, secrets, or configuration files that could expose credentials.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1213 | Data from Information Repositories |
Comments
Secure disposal reduces stale sensitive records in repositories such as document stores, collaboration platforms, or knowledge bases.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1039 | Data from Network Shared Drive |
Comments
Secure disposal reduces obsolete or unnecessary sensitive data left on shared drives, limiting what an adversary can collect from network shares.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1005 | Data from Local System |
Comments
Secure disposal reduces residual sensitive files on endpoints and servers that an adversary could later collect from local storage.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1070.004 | File Deletion |
Comments
The safeguard specifically concerns secure deletion and sanitization of residual data artifacts.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1561 | Disk Wipe |
Comments
This control protects against attacker behaviors that destroy or overwrite data and storage media.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1485 | Data Destruction |
Comments
Secure disposal directly addresses preventing unauthorized recovery or persistence of sensitive data remnants.
References
|